All 3 CVE vulnerabilities found in Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker, with AI-generated Chinese analysis, references, and POCs.
Vendor: expresstech
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-15963 | Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option CWE-89 | 6.5 | Medium | 2026-08-16 |
| CVE-2026-11780 | Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter CWE-79 | 6.4 | Medium | 2026-08-16 |
| CVE-2026-13767 | Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter CWE-89 | 6.5 | Medium | 2026-07-16 |
All 3 known CVE vulnerabilities affecting Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker with full Chinese analysis, references, and POCs where available.