CVE-2022-4033
- EPSS 0.35%
- Veröffentlicht 29.11.2022 21:15:12
- Zuletzt bearbeitet 08.04.2026 18:17:32
The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers to inject content other than ...
CVE-2022-4032
- EPSS 2.71%
- Veröffentlicht 29.11.2022 21:15:12
- Zuletzt bearbeitet 08.04.2026 19:17:54
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injec...
CVE-2022-42883
- EPSS 0.77%
- Veröffentlicht 18.11.2022 23:15:28
- Zuletzt bearbeitet 21.11.2024 07:25:31
Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress.
CVE-2022-40698
- EPSS 0.26%
- Veröffentlicht 18.11.2022 23:15:23
- Zuletzt bearbeitet 21.11.2024 07:21:52
Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
CVE-2022-41652
- EPSS 0.93%
- Veröffentlicht 18.11.2022 19:15:29
- Zuletzt bearbeitet 20.02.2025 20:15:41
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
CVE-2021-36905
- EPSS 0.18%
- Veröffentlicht 17.11.2022 23:15:11
- Zuletzt bearbeitet 21.11.2024 06:14:16
Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2021-36906
- EPSS 0.33%
- Veröffentlicht 03.11.2022 20:15:20
- Zuletzt bearbeitet 20.02.2025 20:15:33
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.
CVE-2021-36898
- EPSS 0.54%
- Veröffentlicht 28.10.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:14:16
Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2021-36864
- EPSS 0.18%
- Veröffentlicht 28.10.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:14:12
Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2021-36863
- EPSS 0.18%
- Veröffentlicht 28.10.2022 16:15:14
- Zuletzt bearbeitet 21.11.2024 06:14:12
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.