目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

ExpressTech 厂商漏洞列表 / CVE 中文分析 44

ExpressTech 厂商相关 44 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

ExpressTech 主要提供企业级应用开发框架,旨在简化后端服务构建流程。截至最新统计,该框架已收录 36 条 CVE,历史上常见漏洞类型包括远程代码执行、跨站脚本及不安全的反序列化问题。其安全特性侧重于中间件层的请求过滤,但早期版本因默认配置宽松曾引发数据泄露风险。开发者需定期更新依赖以修复已知缺陷,确保生产环境的安全性。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-15963 Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option — Quiz and Survey Master (QSM) – Quiz Maker & Survey MakerCWE-89 6.5 Medium2026-08-16
CVE-2026-11780 Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter — Quiz and Survey Master (QSM) – Quiz Maker & Survey MakerCWE-79 6.4 Medium2026-08-16
CVE-2026-13767 Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter — Quiz and Survey Master (QSM) – Quiz Maker & Survey MakerCWE-89 6.5 Medium2026-07-16
CVE-2026-9230 Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-862 4.3 Medium2026-07-03
CVE-2026-9233 Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-862 4.3 Medium2026-06-27
CVE-2026-48867 WordPress Quiz And Survey Master plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability — Quiz And Survey MasterCWE-79 7.1 High2026-06-15
CVE-2026-40787 WordPress Quiz And Survey Master plugin <= 11.0.0 - Cross Site Scripting (XSS) vulnerability — Quiz And Survey MasterCWE-79 7.1 High2026-06-15
CVE-2026-6448 Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-89 4.9 Medium2026-06-05
CVE-2026-5797 Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-74 5.3 Medium2026-04-17
CVE-2026-2412 Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-89 6.5 Medium2026-03-23
CVE-2025-9318 Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-89 6.5 Medium2026-01-06
CVE-2025-9637 Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-862 6.5 Medium2026-01-06
CVE-2025-9294 Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-285 4.3 Medium2026-01-06
CVE-2023-37984 WordPress Quiz And Survey Master plugin <= 8.1.10 - Broken Access Control vulnerability — Quiz And Survey MasterCWE-862 4.3 Medium2024-12-13
CVE-2023-51507 WordPress Quiz And Survey Master plugin <= 8.1.16 - Broken Access Control vulnerability — Quiz And Survey MasterCWE-862 5.3 Medium2024-06-14
CVE-2024-3592 Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-89 9.9 Critical2024-06-07
CVE-2023-28787 WordPress Quiz And Survey Master plugin <= 8.1.4 - Unauthenticated SQL Injection vulnerability — Quiz And Survey MasterCWE-89 9.3 Critical2024-03-26
CVE-2024-27966 WordPress Quiz And Survey Master plugin <= 8.2.2 - Cross Site Scripting (XSS) vulnerability — Quiz And Survey MasterCWE-79 5.9 Medium2024-03-21
CVE-2023-51521 WordPress Quiz And Survey Master plugin <= 8.1.18 - Cross Site Request Forgery (CSRF) vulnerability — Quiz And Survey MasterCWE-352 5.4 Medium2024-03-16
CVE-2023-47834 WordPress Quiz And Survey Master Plugin <= 8.1.13 is vulnerable to Cross Site Scripting (XSS) — Quiz And Survey MasterCWE-79 6.5 Medium2023-11-22
CVE-2023-26524 WordPress Quiz And Survey Master Plugin <= 8.0.10 is vulnerable to Cross Site Request Forgery (CSRF) — Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPressCWE-352 4.3 Medium2023-11-12
CVE-2023-0292 Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletion — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-352 5.4 Medium2023-06-09
CVE-2023-0291 Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletion — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-862 7.2 High2023-06-09
CVE-2022-46862 WordPress Quiz And Survey Master Plugin <= 8.0.7 is vulnerable to Cross Site Request Forgery (CSRF) — Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPressCWE-352 4.3 Medium2023-02-14
CVE-2022-4033 Quiz and Survey Master <= 8.0.4 - Improper Input Validation — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-20 5.3 Medium2022-11-29
CVE-2022-4032 Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answer — Quiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-20 7.2 High2022-11-29
CVE-2022-42883 WordPress Quiz And Survey Master plugin <= 7.3.10 - Sensitive Information Disclosure vulnerability — Quiz And Survey Master (WordPress plugin)CWE-200 5.3 Medium2022-11-18
CVE-2022-40698 WordPress Quiz And Survey Master plugin <= 7.3.10 - Cross-Site Scripting (XSS) vulnerability — Quiz And Survey Master (WordPress plugin)CWE-79 5.4 Medium2022-11-18
CVE-2022-41652 WordPress Quiz And Survey Master plugin <= 7.3.10 - Bypass vulnerability — Quiz And Survey Master (WordPress plugin) 6.5 Medium2022-11-18
CVE-2021-36905 WordPress Quiz And Survey Master plugin <= 7.3.4 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilities — Quiz And Survey Master (WordPress plugin)CWE-79 5.4 Medium2022-11-17

本页汇总了 ExpressTech 厂商截至目前公开的全部 44 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。