expresstech
Web & CMS Pluginscommercial
Latest CVEs
The 15 most recently published vulnerabilities affecting expresstech.
- CVE-2026-48867WordPress Quiz And Survey Master plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-40787WordPress Quiz And Survey Master plugin <= 11.0.0 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-6448Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters4.9
- CVE-2026-5797Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields5.3
- CVE-2026-2412Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter6.5
- CVE-2025-9318Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter6.5
- CVE-2025-9637Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads6.5
- CVE-2025-9294Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion4.3
- CVE-2024-10679Quiz and Survey Master (QSM) < 9.2.1 - Author+ Stored XSS6.1
- CVE-2023-37984WordPress Quiz And Survey Master plugin <= 8.1.10 - Broken Access Control vulnerability4.3
- CVE-2024-8758Quiz and Survey Master (QSM) < 9.1.3 - Author+ Stored XSS4.8
- CVE-2024-6879Quiz and Survey Master (QSM) < 9.1.1 - Contributor+ Stored XSS4.7
- CVE-2024-6390Quiz and Survey Master (QSM) < 9.1.0 - Contributor+ Stored XSS5.9
- CVE-2024-6025Quiz and Survey Master < 9.0.5 - Contributor+ Stored XSS5.4
- CVE-2024-5606Quiz And Survey Master < 9.0.2 - Contributor+ SQLi8.8