ExpressTech Vulnerabilities and Affected Products
Vulnerabilities associated with Quiz And Survey Master.
Products
Clear product- Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker13 vulnerabilities
- Quiz And Survey Master12 vulnerabilities
- Quiz And Survey Master (WordPress plugin)9 vulnerabilities
- quiz_and_survey_master8 vulnerabilities
- Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress3 vulnerabilities
- Responsive Menu Pro3 vulnerabilities
- Responsive Menu – Create Mobile-Friendly Menu3 vulnerabilities
- Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker1 vulnerability
- Responsive Menu (WordPress plugin)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-48867HIGH | WordPress Quiz And Survey Master plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerabilityUnauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions. CWE-79Jun 15, 2026 | CVSS7.1v3.1 | EPSS0.175% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40787HIGH | WordPress Quiz And Survey Master plugin <= 11.0.0 - Cross Site Scripting (XSS) vulnerabilityUnauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions. CWE-79Jun 15, 2026 | CVSS7.1v3.1 | EPSS0.175% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-37984MEDIUM | WordPress Quiz And Survey Master plugin <= 8.1.10 - Broken Access Control vulnerabilityMissing Authorization vulnerability in ExpressTech Quiz And Survey Master allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through 8.1.10. CWE-862Dec 13, 2024 | CVSS4.3v3.1 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-51507MEDIUM | WordPress Quiz And Survey Master plugin <= 8.1.16 - Broken Access Control vulnerabilityMissing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16. CWE-862Jun 14, 2024 | CVSS5.3v3.1 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28787CRITICAL | WordPress Quiz And Survey Master plugin <= 8.1.4 - Unauthenticated SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4. | CVSS9.3v3.1 | EPSS1.96% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-27966MEDIUM | WordPress Quiz And Survey Master plugin <= 8.2.2 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 8.2.2. CWE-79Mar 21, 2024 | CVSS5.9v3.1 | EPSS0.338% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-51521MEDIUM | WordPress Quiz And Survey Master plugin <= 8.1.18 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.18. CWE-352Mar 16, 2024 | CVSS5.4v3.1 | EPSS0.197% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47834MEDIUM | WordPress Quiz And Survey Master Plugin <= 8.1.13 is vulnerable to Cross Site Scripting (XSS)Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13 versions. CWE-79Nov 22, 2023 | CVSS6.5v3.1 | EPSS0.385% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0182MEDIUM | Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master. CWE-79Jan 17, 2022 | CVSS5.4v3.1 | EPSS0.974% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0181MEDIUM | Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors. CWE-79Jan 17, 2022 | CVSS6.1v3.1 | EPSS1.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0180HIGH | Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page. CWE-352Jan 17, 2022 | CVSS8.8v3.1 | EPSS0.654% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-20792MEDIUM | WordPress Quiz and Survey Master <7.1.14 - Cross-Site ScriptingCross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors. | CVSS6.1v3.1 | EPSS3.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |