Expresstech
Expresstech Quiz AND Survey Master: vulnerabilidades y CVE
Expresstech Quiz AND Survey Master tiene 38 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE38
Últimos 12 meses3
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-9637 | Media (6.5) | 0.27% | — | 6 ene 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all… |
| CVE-2025-9318 | Media (6.5) | 0.26% | — | 6 ene 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to… |
| CVE-2025-9294 | Media (4.3) | 0.22% | — | 6 ene 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions… |
| CVE-2024-10679 | Media (6.1) | 0.33% | — | 25 mar 2025 | The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even… |
| CVE-2024-8758 | Media (4.8) | 0.40% | — | 23 sept 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even… |
| CVE-2024-6879 | Media (4.7) | 0.43% | — | 26 ago 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and… |
| CVE-2024-6390 | Media (5.9) | 0.33% | — | 3 ago 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site… |
| CVE-2024-6025 | Media (5.4) | 0.38% | — | 11 jul 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks |
| CVE-2024-5606 | Alta (8.8) | 0.59% | — | 2 jul 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection… |
| CVE-2024-4934 | Media (5.5) | 0.35% | — | 1 jul 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the… |
| CVE-2023-51507 | Media (5.3) | 0.31% | — | 14 jun 2024 | Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16. |
| CVE-2024-3592 | Media (6.5) | 0.48% | — | 7 jun 2024 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to… |
| CVE-2023-26524 | Alta (8.8) | 0.31% | — | 13 nov 2023 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions. |
| CVE-2023-3575 | Media (5.4) | 0.55% | — | 7 ago 2023 | The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks |
| CVE-2023-0292 | Alta (8.1) | 0.79% | — | 9 jun 2023 | The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the… |
| CVE-2023-0291 | Crítica (9.1) | 2.0% | — | 9 jun 2023 | The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and… |
| CVE-2022-46862 | Alta (8.8) | 0.38% | — | 14 feb 2023 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions. |
| CVE-2022-4033 | Media (5.3) | 0.73% | — | 29 nov 2022 | The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows… |
| CVE-2022-4032 | Media (6.1) | 0.79% | — | 29 nov 2022 | The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that… |
| CVE-2022-42883 | Alta (7.5) | 0.71% | — | 18 nov 2022 | Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress. |
| CVE-2022-40698 | Media (6.1) | 0.45% | — | 18 nov 2022 | Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. |
| CVE-2022-41652 | Crítica (9.8) | 0.75% | — | 18 nov 2022 | Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. |
| CVE-2021-36905 | Media (5.4) | 0.47% | — | 17 nov 2022 | Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress. |
| CVE-2021-36906 | Alta (8.8) | 0.58% | — | 3 nov 2022 | Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. |
| CVE-2021-36898 | Alta (7.2) | 0.91% | — | 28 oct 2022 | Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress. |
| CVE-2021-36864 | Media (5.4) | 0.46% | — | 28 oct 2022 | Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. |
| CVE-2021-36863 | Media (5.4) | 0.50% | — | 28 oct 2022 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. |
| CVE-2022-0182 | Media (5.4) | 0.97% | — | 17 ene 2022 | Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master. |
| CVE-2022-0181 | Media (6.1) | 1.3% | — | 17 ene 2022 | Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors. |
| CVE-2022-0180 | Alta (8.8) | 0.65% | — | 17 ene 2022 | Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially… |