VYPR
Vendor

Quizandsurveymaster

Products
2
CVEs
5
Across products
6
Status
Private

Products

2

Recent CVEs

5
  • CVE-2023-47834MedNov 23, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13 versions.

  • CVE-2019-9575MedMar 5, 2019
    risk 0.40cvss 6.1epss 0.02

    The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.

  • CVE-2024-4934MedJul 1, 2024
    risk 0.36cvss 5.5epss 0.00

    The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site…

  • CVE-2019-17599MedDec 13, 2019
    risk 0.33cvss 6.1epss 0.02

    The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The…

  • CVE-2021-36865LowSep 30, 2022
    risk 0.25cvss 3.8epss 0.00

    Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.