| CVE-2026-5797 | Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 5.3 | 2026-04-17 05:29:27 | Deep Dive |
| CVE-2026-2412 | Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 6.5 | 2026-03-23 22:25:40 | Deep Dive |
| CVE-2026-26370 | WordPress plugin Survey Maker 跨站脚本漏洞 | Ays Pro | Survey Maker | - | - | 2026-02-20 07:42:15 | Deep Dive |
| CVE-2019-25297 | Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 Stored XSS | Assaf Parag | Poll, Survey & Quiz Maker Plugin by Opinion Stage | 中危 | - | 2026-01-16 20:14:10 | Deep Dive |
| CVE-2025-9637 | Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 6.5 | 2026-01-06 09:20:59 | Deep Dive |
| CVE-2025-9318 | Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 6.5 | 2026-01-06 09:20:59 | Deep Dive |
| CVE-2025-9294 | Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 4.3 | 2026-01-06 08:21:49 | Deep Dive |
| CVE-2025-68594 | WordPress Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin <= 19.12.0 - Broken Access Control vulnerability | Opinion Stage | Poll, Survey & Quiz Maker Plugin by Opinion Stage | Medium | 5.3 | 2025-12-24 13:10:45 | Deep Dive |
| CVE-2025-13143 | Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnection | assafp | Quiz, Poll & Survey Maker by Opinion Stage | Medium | 4.3 | 2025-11-27 05:31:57 | Deep Dive |
| CVE-2025-64276 | WordPress Survey Maker plugin <= 5.1.9.4 - Broken Access Control vulnerability | Ays Pro | Survey Maker | 中危 | - | 2025-11-13 09:24:32 | Deep Dive |
| CVE-2025-12891 | Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Information Exposure | ays-pro | Survey Maker | Medium | 5.3 | 2025-11-13 04:28:01 | Deep Dive |
| CVE-2025-12892 | Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Limited Option Update | ays-pro | Survey Maker | Medium | 5.3 | 2025-11-13 03:27:38 | Deep Dive |
| CVE-2025-48098 | WordPress Survey Maker plugin <= 5.1.8.8 - Cross Site Scripting (XSS) vulnerability | Ays Pro | Survey Maker | - | - | 2025-10-22 14:32:07 | Deep Dive |
| CVE-2025-48095 | WordPress Survey Maker plugin <= 5.1.8.8 - Cross Site Scripting (XSS) vulnerability | Ays Pro | Survey Maker | - | - | 2025-10-22 14:32:07 | Deep Dive |
| CVE-2025-53328 | WordPress Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin <= 19.11.0 - Local File Inclusion Vulnerability | Opinion Stage | Poll, Survey & Quiz Maker Plugin by Opinion Stage | High | 7.5 | 2025-08-28 12:37:28 | Deep Dive |
| CVE-2025-3880 | Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.9.0 - Incorrect Authorization to Authenticated (Contributor+) Plugin Settings Update | assafp | Quiz, Poll & Survey Maker by Opinion Stage | Medium | 4.3 | 2025-06-17 11:23:37 | Deep Dive |
| CVE-2025-32275 | WordPress Survey Maker plugin <= 5.1.6.3 - Bypass vulnerability | Ays Pro | Survey Maker | - | - | 2025-04-10 08:09:48 | Deep Dive |
| CVE-2025-22664 | WordPress Survey Maker Plugin <= 5.1.3.5 - Cross Site Scripting (XSS) vulnerability | Ays Pro | Survey Maker | Medium | 5.9 | 2025-02-04 14:21:58 | Deep Dive |
| CVE-2024-13505 | Survey Maker <= 5.1.3.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Survey Question | ays-pro | Survey Maker | Medium | 5.5 | 2025-01-26 11:23:13 | Deep Dive |
| CVE-2023-22697 | WordPress Survey Maker plugin <= 3.2.0 - Broken Access Control vulnerability | Ays Pro | Survey Maker | Medium | 5.3 | 2024-12-13 14:22:13 | Deep Dive |