ExpressTech Vulnerabilities and Affected Products
Vulnerabilities associated with Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker.
Products
Clear product- Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker13 vulnerabilities
- Quiz And Survey Master12 vulnerabilities
- Quiz And Survey Master (WordPress plugin)9 vulnerabilities
- quiz_and_survey_master8 vulnerabilities
- Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress3 vulnerabilities
- Responsive Menu Pro3 vulnerabilities
- Responsive Menu – Create Mobile-Friendly Menu3 vulnerabilities
- Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker1 vulnerability
- Responsive Menu (WordPress plugin)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-13767MEDIUM | Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' ParameterThe Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient preparation on the existing SQL query built in qsm_options_questions_tab_content() at line 143, where the stored page IDs are interpolated into an IN() clause via implode() with no … CWE-89Jul 16, 2026 | CVSS6.5v3.1 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |