CVE-2023-0292
- EPSS 0.79%
- Veröffentlicht 09.06.2023 06:15:49
- Zuletzt bearbeitet 08.04.2026 19:17:59
The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. ...
CVE-2023-0291
- EPSS 2.03%
- Veröffentlicht 09.06.2023 06:15:48
- Zuletzt bearbeitet 08.04.2026 18:17:41
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possib...
CVE-2022-46862
- EPSS 0.38%
- Veröffentlicht 14.02.2023 12:15:15
- Zuletzt bearbeitet 21.11.2024 07:31:11
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions.
CVE-2022-4033
- EPSS 0.67%
- Veröffentlicht 29.11.2022 21:15:12
- Zuletzt bearbeitet 08.04.2026 18:17:32
The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers to inject content other than ...
CVE-2022-4032
- EPSS 0.72%
- Veröffentlicht 29.11.2022 21:15:12
- Zuletzt bearbeitet 08.04.2026 19:17:54
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injec...
CVE-2022-42883
- EPSS 0.65%
- Veröffentlicht 18.11.2022 23:15:28
- Zuletzt bearbeitet 21.11.2024 07:25:31
Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress.
CVE-2022-40698
- EPSS 0.42%
- Veröffentlicht 18.11.2022 23:15:23
- Zuletzt bearbeitet 21.11.2024 07:21:52
Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
CVE-2022-41652
- EPSS 0.69%
- Veröffentlicht 18.11.2022 19:15:29
- Zuletzt bearbeitet 20.02.2025 20:15:41
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
CVE-2021-36905
- EPSS 0.43%
- Veröffentlicht 17.11.2022 23:15:11
- Zuletzt bearbeitet 21.11.2024 06:14:16
Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2021-36906
- EPSS 0.53%
- Veröffentlicht 03.11.2022 20:15:20
- Zuletzt bearbeitet 20.02.2025 20:15:33
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.