Extension WordPress
Vulnérabilités Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker, page 2
Cette page rassemble les failles publiées pour Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker
67 fiches
Quiz and Survey Master (QSM) <= 9.1.2 – Authenticated (Admin+) Stored Cross-Site Scripting
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.1.2 due to insufficient input sanitization and…
*-9.1.2
9.1.3
02/09/2024
Quiz and Survey Master (QSM) <= 9.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the redirect URL in all versions up to, and including, 9.1.0 due to insufficient input sanitization…
*-9.1.0
9.1.1
05/08/2024
Quiz and Survey Master <= 9.0.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz retake button label in all versions up to, and including, 9.0.5 due to insufficient…
*-9.0.5
9.1.0
13/07/2024
Quiz and Survey Master <= 9.0.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 9.0.4 due to insufficient input sanitization and output escaping. This…
*-9.0.4
9.0.5
20/06/2024
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 9.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via quiz fields in all versions up to, and including, 9.0.1 due to insufficient input sanitization and…
*-9.0.1
9.0.2
10/06/2024
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 – Authenticated (Contributor+) SQL Injection
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping…
*-9.0.1
9.0.2
06/06/2024
Quiz And Survey Master <= 8.2.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.2.2 due to insufficient input…
*-8.2.2
8.2.3
13/03/2024
Quiz And Survey Master <= 8.1.16 – Missing Authorization
The Quiz And Survey Master plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on one of its functions in versions up to, and including, 8.1.16. This makes…
*-8.1.16
8.1.17
27/12/2023
Quiz And Survey Master <= 8.1.18 – Cross-Site Request Forgery
The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.1.18. This is due to missing or incorrect nonce validation on several functions. This makes it possible for…
*-8.1.18
8.1.19
27/12/2023
Quiz And Survey Master <= 8.1.13 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 8.1.13 due to insufficient…
*-8.1.13
8.1.14
16/11/2023
Quiz And Survey Master <= 8.1.15 – Cross-Site Request Forgery via 'display_results'
The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.1.15. This is due to missing or incorrect nonce validation on the 'display_results' function. This makes it possible…
[*, 8.1.15)
8.1.16
12/09/2023
Quiz And Survey Master <= 8.1.10 – Excessive Quiz Attempts
The Quiz And Survey Master plugin for WordPress is vulnerable to exessive quiz attempts due to a missing validation checks on the ajax_submit_results() function in versions up to, and including, 8.1.10. This makes it possible for unauthenticated attackers…
*-8.1.10
8.1.11
17/07/2023
Quiz And Survey Master <= 8.1.10 – Authenticated (Contributor+) Stored Cross-Site Scripting via Question Title
The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a question title in versions up to, and including 8.1.10 due to insufficient input sanitization and output escaping. This makes it possible for…
*-8.1.10
8.1.11
17/07/2023
Quiz and Survey Master <= 8.1.4 – Unauthenticated SQL Injection
The Quiz and Survey Master plugin for WordPress is vulnerable to SQL Injection via the 'question_ids_[XX]' cookie in versions up to, and including, 8.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-8.1.4
8.1.5
16/04/2023
Quiz And Survey Master <= 8.0.10 – Cross-Site Request Forgery to Quiz Restoration
The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.10. This is due to missing or incorrect nonce validation on the qsm_restore_function function. This makes it possible…
*-8.0.10
8.1.0
28/02/2023
Quiz And Survey Master <= 8.0.8 – Unauthenticated Arbitrary Media Deletion
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible…
*-8.0.8
8.0.9
15/02/2023
Quiz And Survey Master <= 8.0.8 – Cross-Site Request Forgery to Arbitrary Media Deletion
The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This…
*-8.0.8
8.0.9
08/02/2023
Quiz And Survey Master <= 8.0.7 – Cross-Site Request Forgery
The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.7. This is due to missing or incorrect nonce validation on the qsm_update_text_message function. This makes it possible…
*-8.0.7
8.0.8
16/12/2022
Quiz and Survey Master <= 8.0.4 – Unauthenticated iFrame Injection via Paragraph and Short Answer
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be…
*-8.0.4
8.0.5
29/11/2022
Quiz and Survey Master <= 8.0.4 – Improper Input Validation
The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers to inject content other than…
*-8.0.4
8.0.5
16/11/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.