Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.15%—Quizandsurveymaster Quiz AND Survey MasterAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
AplazadaMedia (5.3)0.31%—Quizandsurveymaster Quiz AND Survey MasterAI11/9/202611/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.
AplazadaBaja (2.7)0.30%—Quizandsurveymaster Quiz AND Survey MasterAI28/8/202628/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.
AplazadaBaja (2.7)0.30%—Expressivequiz Quiz AND Survey MasterAI19/8/202626/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient…
AplazadaBaja (2.7)0.28%—Quizandsurveymaster Quiz AND Survey MasterAI19/8/202626/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.
AplazadaMedia (6.5)0.45%—Quizandsurveymaster Quiz AND Survey MasterAI16/8/202620/8/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaMedia (6.4)0.42%—Expresstech Quiz Survey MasterAI16/8/202620/8/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaMedia (4.8)0.24%—Quizandsurveymaster Quiz AND Survey MasterAI4/8/202626/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser of any user viewing the affected quiz.
AplazadaBaja (2.7)0.28%—Quizandsurveymaster Quiz AND Survey MasterAI28/7/202628/7/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.
AplazadaMedia (5.3)0.37%—Quizandsurveymaster Quiz AND Survey MasterAI27/7/202627/7/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to…
AplazadaAlta (8.5)0.36%—Quizandsurveymaster Quiz AND Survey MasterAI23/7/202623/7/2026
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
AplazadaMedia (4.3)0.49%—Quizandsurveymaster Quiz AND Survey MasterAI3/7/20266/7/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaMedia (4.3)0.47%—Quizandsurveymaster Quiz AND Survey MasterAI27/6/202629/6/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaAlta (7.1)0.25%—Expressionengine Quiz AND Survey MasterAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.
AplazadaAlta (7.1)0.25%—Expressionengine Quiz AND Survey MasterAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.
AplazadaMedia (4.9)0.60%—Expressionengine Quiz AND Survey MasterAI6/6/202623/7/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaMedia (5.3)0.67%—Quizandsurveymaster Quiz AND Survey MasterAI17/4/202617/6/2026
The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and…
AplazadaMedia (6.5)0.32%—Quizandsurveymaster Quiz AND Survey MasterAI23/3/202617/6/2026
The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and including, 10.3.5. This is due to insufficient sanitization of user-supplied input before being used in a SQL query. The sanitize_text_field() function applied to the…
AplazadaAlta (8.5)0.27%—Expresstechsystems Quiz AND Survey MasterAI20/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.3.1.
AplazadaMedia (4.3)0.19%—Expresstechsystems Quiz AND Survey MasterAI19/2/202617/6/2026
Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4.
AplazadaMedia (5.3)0.33%—Expresstechsystems Quiz AND Survey MasterAI19/2/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4.
AplazadaMedia (4.3)0.18%—Expresstechsystems Quiz AND Survey MasterAI22/1/202617/6/2026
Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.3.
AnalizadaMedia (6.5)0.27%—Expresstech Quiz AND Survey Master6/1/202630/9/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, and including, 10.3.1. This makes it possible for unauthenticated attackers to view…
AnalizadaMedia (6.5)0.26%—Expresstech Quiz AND Survey Master6/1/202630/9/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
ModificadaMedia (4.3)0.22%—Expresstech Quiz AND Survey Master6/1/202630/9/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attackers, with…