Vulnerabilities > Expresstech > Quiz AND Survey Master > 7.3.5
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-11-29 | CVE-2022-4032 | Cross-site Scripting vulnerability in Expresstech Quiz and Survey Master The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. | 6.1 |
2022-11-29 | CVE-2022-4033 | Improper Input Validation vulnerability in Expresstech Quiz and Survey Master The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers to inject content other than the specified value (i.e. | 5.3 |
2022-11-18 | CVE-2022-40698 | Cross-site Scripting vulnerability in Expresstech Quiz and Survey Master Auth. | 6.1 |
2022-11-18 | CVE-2022-42883 | Unspecified vulnerability in Expresstech Quiz and Survey Master Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress. | 7.5 |
2022-11-18 | CVE-2022-41652 | Unspecified vulnerability in Expresstech Quiz and Survey Master Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. | 9.8 |
2022-11-03 | CVE-2021-36906 | Authorization Bypass Through User-Controlled Key vulnerability in Expresstech Quiz and Survey Master Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. | 8.8 |
2022-01-17 | CVE-2022-0180 | Cross-Site Request Forgery (CSRF) vulnerability in Expresstech Quiz and Survey Master Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page. | 8.8 |
2022-01-17 | CVE-2022-0181 | Cross-site Scripting vulnerability in Expresstech Quiz and Survey Master Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors. | 6.1 |
2022-01-17 | CVE-2022-0182 | Cross-site Scripting vulnerability in Expresstech Quiz and Survey Master Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master. | 5.4 |