Quizandsurveymaster
Quizandsurveymaster Quiz AND Survey Master: vulnerabilidades y CVE
Quizandsurveymaster Quiz AND Survey Master tiene 17 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses13
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97289 | Alta (7.1) | 0.15% | — | 30 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. |
| CVE-2026-62140 | Media (5.3) | 0.31% | — | 11 sept 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. |
| CVE-2026-79615 | Baja (2.7) | 0.30% | — | 28 ago 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to… |
| CVE-2026-14825 | Baja (2.7) | 0.28% | — | 19 ago 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to… |
| CVE-2026-15963 | Media (6.5) | 0.45% | — | 16 ago 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to… |
| CVE-2026-14824 | Media (4.8) | 0.24% | — | 4 ago 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to… |
| CVE-2026-14821 | Baja (2.7) | 0.28% | — | 28 jul 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates. |
| CVE-2026-14820 | Media (5.3) | 0.37% | — | 27 jul 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid… |
| CVE-2026-65454 | Alta (8.5) | 0.36% | — | 23 jul 2026 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. |
| CVE-2026-9230 | Media (4.3) | 0.49% | — | 3 jul 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying… |
| CVE-2026-9233 | Media (4.3) | 0.47% | — | 27 jun 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying… |
| CVE-2026-5797 | Media (5.3) | 0.67% | — | 17 abr 2026 | The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode()… |
| CVE-2026-2412 | Media (6.5) | 0.32% | — | 23 mar 2026 | The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and including, 10.3.5. This is due to insufficient sanitization of… |
| CVE-2025-6790 | Media (4.3) | 0.12% | — | 14 ago 2025 | The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. |
| CVE-2023-47834 | Media (5.4) | 0.39% | — | 23 nov 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13 versions. |
| CVE-2021-36865 | Media (4.3) | 0.50% | — | 30 sept 2022 | Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz. |
| CVE-2019-9575 | Media (6.1) | 1.6% | — | 5 mar 2019 | The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.