VYPR

Quiz and Survey Master (QSM)

by WordPress

CVEs (66)

  • CVE-2026-14824MedAug 4, 2026
    risk 0.00cvss 4.8epss 0.00

    The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser…

  • CVE-2026-14821LowJul 28, 2026
    risk 0.00cvss 2.7epss 0.00

    The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.

  • CVE-2026-14820MedJul 27, 2026
    risk 0.00cvss 5.3epss 0.00

    The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers…

  • CVE-2026-65454HigJul 23, 2026
    risk 0.00cvss 8.5epss 0.00

    Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

  • CVE-2026-9230MedJul 3, 2026
    risk 0.00cvss 4.3epss 0.00

    The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-9233MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

Page 4 of 4