VendorsExpress Techquiz_and_survey_masterany version
Vulnerabilities

Express Tech Quiz and Survey Master any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

38CVEs
CVE-2020-35949
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload, and thus the attacker could use text/plain for a .php file.
Published 2021-01-01 · Modified
10.0EPSS 0.049
CVE-2020-35951
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).
Published 2021-01-01 · Modified
9.9EPSS 0.763
CVE-2024-3592
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection
Published 2024-06-07 · Modified
9.9EPSS 0.005
CVE-2022-41652
WordPress Quiz And Survey Master plugin <= 7.3.10 - Bypass vulnerability
Published 2022-11-18 · Modified
9.8EPSS 0.007
CVE-2023-0291
Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletion
Published 2023-06-09 · Modified
9.1EPSS 0.020
CVE-2021-24221
Quiz And Survey Master < 7.1.12 - Authenticated SQL injection via shortcode
Published 2021-04-12 · Modified
8.8EPSS 0.019
CVE-2022-0180
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.
Published 2022-01-17 · Modified
8.8EPSS 0.007
CVE-2024-5606
Quiz And Survey Master < 9.0.2 - Contributor+ SQLi
Published 2024-07-02 · Modified
8.8EPSS 0.006
CVE-2021-36906
WordPress Quiz And Survey Master plugin <= 7.3.6 - Multiple Insecure direct object references (IDOR) vulnerabilities
Published 2022-11-03 · Modified
8.8EPSS 0.006
CVE-2022-46862
WordPress Quiz And Survey Master Plugin <= 8.0.7 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-02-14 · Modified
8.8EPSS 0.004
CVE-2023-26524
WordPress Quiz And Survey Master Plugin <= 8.0.10 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-11-12 · Modified
8.8EPSS 0.003
CVE-2023-0292
Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletion
Published 2023-06-09 · Modified
8.1EPSS 0.008
CVE-2021-36898
WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. SQL Injection (SQLi) vulnerability
Published 2022-10-28 · Modified
7.5EPSS 0.009
CVE-2022-42883
WordPress Quiz And Survey Master plugin <= 7.3.10 - Sensitive Information Disclosure vulnerability
Published 2022-11-18 · Modified
7.5EPSS 0.007
CVE-2022-4032
Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answer
Published 2022-11-29 · Modified
7.2EPSS 0.008
CVE-2016-11085
php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.
Published 2020-08-16 · Modified
6.5EPSS 0.010
CVE-2024-6025
Quiz and Survey Master < 9.0.5 - Contributor+ Stored XSS
Published 2024-07-11 · Modified
6.5EPSS 0.004
CVE-2025-9637
Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads
Published 2026-01-06 · Analyzed
6.5EPSS 0.003
CVE-2025-9318
Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter
Published 2026-01-06 · Analyzed
6.5EPSS 0.003
CVE-2021-20792
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
Published 2021-08-18 · Modified
6.1EPSS 0.034
CVE-2019-17599
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
Published 2019-12-13 · Modified
6.1EPSS 0.017
CVE-2022-0181
Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors.
Published 2022-01-17 · Modified
6.1EPSS 0.013
CVE-2021-24368
Quiz And Survey Master < 7.1.18 - Reflected Cross-Site Scripting (XSS)
Published 2021-06-20 · Modified
6.1EPSS 0.008
CVE-2022-40698
WordPress Quiz And Survey Master plugin <= 7.3.10 - Cross-Site Scripting (XSS) vulnerability
Published 2022-11-18 · Modified
6.1EPSS 0.004
CVE-2024-10679
Quiz and Survey Master (QSM) < 9.2.1 - Author+ Stored XSS
Published 2025-03-25 · Analyzed
6.1EPSS 0.003
CVE-2024-6390
Quiz and Survey Master (QSM) < 9.1.0 - Contributor+ Stored XSS
Published 2024-08-03 · Analyzed
5.9EPSS 0.003
CVE-2024-4934
Quiz And Survey Master < 9.0.2 - Contributor+ Stored XSS
Published 2024-07-01 · Analyzed
5.5EPSS 0.004
CVE-2022-0182
Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.
Published 2022-01-17 · Modified
5.4EPSS 0.010
CVE-2023-3575
Quiz And Survey Master < 8.1.11 - Contributor+ Stored XSS
Published 2023-08-07 · Modified
5.4EPSS 0.005
CVE-2021-36863
WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
Published 2022-10-28 · Modified
5.4EPSS 0.005
CVE-2021-36905
WordPress Quiz And Survey Master plugin <= 7.3.4 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilities
Published 2022-11-17 · Modified
5.4EPSS 0.005
CVE-2021-36864
WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. Reflected Cross-Site Scripting (XSS) vulnerability
Published 2022-10-28 · Modified
5.4EPSS 0.004
CVE-2022-4033
Quiz and Survey Master <= 8.0.4 - Improper Input Validation
Published 2022-11-29 · Modified
5.3EPSS 0.007
CVE-2023-51507
WordPress Quiz And Survey Master plugin <= 8.1.16 - Broken Access Control vulnerability
Published 2024-06-14 · Modified
5.3EPSS 0.003
CVE-2021-24691
Quiz And Survey Master < 7.3.2 - Admin+ Stored Cross-Site Scripting
Published 2021-10-11 · Modified
4.8EPSS 0.006
CVE-2024-8758
Quiz and Survey Master (QSM) < 9.1.3 - Author+ Stored XSS
Published 2024-09-23 · Modified
4.8EPSS 0.004
CVE-2024-6879
Quiz and Survey Master (QSM) < 9.1.1 - Contributor+ Stored XSS
Published 2024-08-26 · Analyzed
4.7EPSS 0.004
CVE-2025-9294
Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion
Published 2026-01-06 · Modified
4.3EPSS 0.002