Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses affecting Quiz and Survey Master (QSM), specifically categorized under the Easy Quiz and Survey Maker product line. It serves as a centralized resource for tracking vulnerabilities associated with this popular WordPress plugin used for creating quizzes and surveys. The content herein aggregates security issues reported by vendors, independent researchers, and automated scanning systems. It covers vulnerabilities disclosed over the past several years, including critical flaws in input validation, authentication bypasses, and cross-site scripting risks that have been publicly acknowledged or patched. The collection includes various weakness types such as those classified under Common Weakness Enumeration (CWE) identifiers, reflecting the diverse nature of security lapses found in the software. Users can utilize this page to track the vendor’s advisory history and understand how specific weakness classes manifest within this product. By reviewing the chronological list of vulnerabilities, developers and administrators can assess the security posture of their installations, identify outdated versions that may still be at risk, and prioritize patching efforts. This historical view helps in understanding the evolution of security standards for the product and provides context for current threat landscapes. It is designed for technical professionals seeking factual data rather than promotional material, enabling informed decisions about deployment and maintenance strategies. The information is presented objectively to support compliance audits and security assessments.

Vendor: expresstech

CVE IDTitleCVSSSeverityPublished
CVE-2026-9230 Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure CWE-862 4.3 Medium2026-07-03
CVE-2026-9233 Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action CWE-862 4.3 Medium2026-06-27
CVE-2026-6448 Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters CWE-89 4.9 Medium2026-06-05
CVE-2026-5797 Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields CWE-74 5.3 Medium2026-04-17
CVE-2026-2412 Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter CWE-89 6.5 Medium2026-03-23
CVE-2025-9637 Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads CWE-862 6.5 Medium2026-01-06
CVE-2025-9318 Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter CWE-89 6.5 Medium2026-01-06
CVE-2025-9294 Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion CWE-285 4.3 Medium2026-01-06
CVE-2024-3592 Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection CWE-89 9.9 Critical2024-06-07
CVE-2023-0292 Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletion CWE-352 5.4 Medium2023-06-09
CVE-2023-0291 Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletion CWE-862 7.2 High2023-06-09
CVE-2022-4033 Quiz and Survey Master <= 8.0.4 - Improper Input Validation CWE-20 5.3 Medium2022-11-29
CVE-2022-4032 Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answer CWE-20 7.2 High2022-11-29

All 13 known CVE vulnerabilities affecting Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker with full Chinese analysis, references, and POCs where available.