Extension WordPress
Vulnérabilités Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker, page 3
Cette page rassemble les failles publiées pour Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker
67 fiches
Quiz And Survey Master <= 7.3.10 – Cross-Site Request Forgery
The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.3.10. This is due to missing or incorrect nonce validation on several of its functions. This makes it…
*-7.3.10
7.3.11
23/10/2022
Quiz And Survey Master <= 7.3.10 – Sensitive Information Disclosure
The Quiz And Survey Master plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.3.10. This could allow unauthenticated attackers to extract sensitive user or configuration data.
*-7.3.10
7.3.11
21/10/2022
Quiz And Survey Master <= 7.3.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 7.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-7.3.4
7.3.5
21/10/2022
Quiz And Survey Master <= 7.3.4 – Multiple Authenticated (Contributor+) Stored Cross-Site Scripting
The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 7.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-7.3.4
7.3.5
21/10/2022
Quiz And Survey Master <= 7.3.10 – Missing Authorization
The Quiz And Survey Master plugin for WordPress is vulnerable to authorization bypass due to a missing user validations on the qsm_clear_audit_data function in versions up to, and including, 7.3.10. This makes it possible for unauthenticated attackers to…
*-7.3.10
7.3.11
21/10/2022
Quiz And Survey Master <= 7.3.4 – Reflected Cross-Site Scripting
The Quiz And Survey Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 7.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-7.3.4
7.3.5
21/10/2022
Quiz And Survey Master <= 7.3.10 – Unauthenticated Stored Cross-Site Scripting
The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level…
*-7.3.10
7.3.11
21/10/2022
Quiz And Survey Master <= 7.3.6 – Insecure Direct Object Reference
The Quiz And Survey Master plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 7.3.6. This is due to insufficient validation on a user controlled key. This makes it possible for…
*-7.3.6
7.3.7
21/10/2022
Quiz And Survey Master <= 7.3.4 – Authenticated (Administrator+) SQL Injection
The Quiz And Survey Master plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and including, 7.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-7.3.4
7.3.5
21/10/2022
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 7.3.4 – Insecure Direct Object Reference
The Quiz And Survey Master plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 7.3.4. This is due to insufficient validation on the key controlling a quiz's id. This makes it…
*-7.3.4
7.3.5
29/09/2022
Quiz And Survey Master <= 7.3.6 – Reflected Cross-Site Scripting
Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors.
*-7.3.6
7.3.7
12/01/2022
Quiz And Survey Master <= 7.3.6 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.
*-7.3.5
7.3.7
12/01/2022
Quiz And Survey Master <= 7.3.6 – Stored Cross-Site Scripting
Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.
*-7.3.6
7.3.7
12/01/2022
Quiz and Survey Master <= 7.1.13 – Cross-Site Scripting
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
*-7.1.13
7.1.14
13/09/2021
Quiz And Survey Master <= 7.3.1 – Admin+ Stored Cross-Site Scripting
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html…
*-7.3.1
7.3.2
13/09/2021
Quiz and Survey Master <= 7.1.13 – SQL Injection
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
*-7.1.13
7.1.14
10/08/2021
Quiz And Survey Master <= 7.1.17 – Reflected Cross-Site Scripting
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue.…
*-7.1.17
7.1.18
03/06/2021
Quiz And Survey Master <= 7.1.18 – Cross-Site Scripting
The Quiz And Survey Master plugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.1.18 due to insufficient input sanitization and output escaping on the IP value. This makes it possible for…
[*, 7.1.19)
7.1.19
03/06/2021
Quiz And Survey Master <= 7.1.11 – Authenticated SQL injection via shortcode
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL…
*-7.1.11
7.1.12
26/03/2021
Quiz and Survey Master <= 7.0.1 – Arbitrary File Upload
The Quiz and Survey Master plugin for WordPress is vulnerable to arbitrary file uploads due to missing filename sanitization in the qsm_upload_image_fd_question() function in versions up to, and including, 7.0.1. This makes it possible for unauthenticated attackers to…
*-7.0.1
7.0.2
29/08/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.