Vulnerabilities (CVE)

Filtered by vendor Expresstech Subscribe
Filtered by product Quiz And Survey Master
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3575 1 Expresstech 1 Quiz And Survey Master 2023-08-09 N/A 5.4 MEDIUM
The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2022-0181 1 Expresstech 1 Quiz And Survey Master 2022-01-24 4.3 MEDIUM 6.1 MEDIUM
Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors.
CVE-2022-0182 1 Expresstech 1 Quiz And Survey Master 2022-01-24 3.5 LOW 5.4 MEDIUM
Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.
CVE-2021-24691 1 Expresstech 1 Quiz And Survey Master 2021-10-15 3.5 LOW 4.8 MEDIUM
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2021-20792 1 Expresstech 1 Quiz And Survey Master 2021-08-25 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
CVE-2021-24368 1 Expresstech 1 Quiz And Survey Master 2021-06-25 4.3 MEDIUM 6.1 MEDIUM
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link
CVE-2016-11085 1 Expresstech 1 Quiz And Survey Master 2020-08-21 4.3 MEDIUM 6.5 MEDIUM
php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.
CVE-2019-17599 1 Expresstech 1 Quiz And Survey Master 2019-12-17 4.3 MEDIUM 6.1 MEDIUM
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.