Extension WordPress

Vulnérabilités Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker, page 3

Cette page rassemble les failles publiées pour Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker, leurs plages de versions affectées et les correctifs signalés dans la base locale.

67Vulnérabilités
4Critiques
67Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

67 fiches

CVE-2021-36863 Moyenne · 6,4
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz And Survey Master <= 7.3.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 7.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-7.3.4

Correctif

7.3.5

Publication

21/10/2022

CVE-2021-36905 Moyenne · 6,4
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz And Survey Master <= 7.3.4 – Multiple Authenticated (Contributor+) Stored Cross-Site Scripting

The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 7.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-7.3.4

Correctif

7.3.5

Publication

21/10/2022

CVE-2022-41652 Moyenne · 4,3
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz And Survey Master <= 7.3.10 – Missing Authorization

The Quiz And Survey Master plugin for WordPress is vulnerable to authorization bypass due to a missing user validations on the qsm_clear_audit_data function in versions up to, and including, 7.3.10. This makes it possible for unauthenticated attackers to…

Versions affectées

*-7.3.10

Correctif

7.3.11

Publication

21/10/2022

CVE-2021-36864 Moyenne · 6,1
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz And Survey Master <= 7.3.4 – Reflected Cross-Site Scripting

The Quiz And Survey Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 7.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-7.3.4

Correctif

7.3.5

Publication

21/10/2022

CVE-2022-40698 Élevée · 7,2
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz And Survey Master <= 7.3.10 – Unauthenticated Stored Cross-Site Scripting

The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-7.3.10

Correctif

7.3.11

Publication

21/10/2022

CVE-2021-36898 Élevée · 7,2
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz And Survey Master <= 7.3.4 – Authenticated (Administrator+) SQL Injection

The Quiz And Survey Master plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and including, 7.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

Versions affectées

*-7.3.4

Correctif

7.3.5

Publication

21/10/2022

CVE-2021-36865 Moyenne · 5,4
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 7.3.4 – Insecure Direct Object Reference

The Quiz And Survey Master plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 7.3.4. This is due to insufficient validation on the key controlling a quiz's id. This makes it…

Versions affectées

*-7.3.4

Correctif

7.3.5

Publication

29/09/2022

CVE-2021-24691 Moyenne · 4,8
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz And Survey Master <= 7.3.1 – Admin+ Stored Cross-Site Scripting

The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html…

Versions affectées

*-7.3.1

Correctif

7.3.2

Publication

13/09/2021

CVE-2021-24368 Moyenne · 6,1
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz And Survey Master <= 7.1.17 – Reflected Cross-Site Scripting

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue.…

Versions affectées

*-7.1.17

Correctif

7.1.18

Publication

03/06/2021

CVE-2021-24221 Élevée · 8,8
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz And Survey Master <= 7.1.11 – Authenticated SQL injection via shortcode

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL…

Versions affectées

*-7.1.11

Correctif

7.1.12

Publication

26/03/2021

Vulnérabilité Critique · 9,8
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

Quiz and Survey Master <= 7.0.1 – Arbitrary File Upload

The Quiz and Survey Master plugin for WordPress is vulnerable to arbitrary file uploads due to missing filename sanitization in the qsm_upload_image_fd_question() function in versions up to, and including, 7.0.1. This makes it possible for unauthenticated attackers to…

Versions affectées

*-7.0.1

Correctif

7.0.2

Publication

29/08/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités