Showing 1 vulnerability on this page for Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Signals CISA KEV Ransomware Nuclei
ExpressTech vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter

The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient preparation on the existing SQL query built in qsm_options_questions_tab_content() at line 143, where the stored page IDs are interpolated into an IN() clause via implode() with no

CWE-89Jul 16, 2026
CVSS6.5v3.1EPSS0.249%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX