expresstech CVE Vulnerabilities & Metrics

Focus on expresstech vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About expresstech Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with expresstech. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total expresstech CVEs: 36
Earliest CVE date: 14 Aug 2019, 16:15 UTC
Latest CVE date: 23 Sep 2024, 06:15 UTC

Latest CVE reference: CVE-2024-8758

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 5

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 25.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 25.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical expresstech CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.47

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 22
4.0-6.9 13
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS expresstech CVEs

These are the five CVEs with the highest CVSS scores for expresstech, sorted by severity first and recency.

All CVEs for expresstech

CVE-2024-8758 expresstech vulnerability CVSS: 0 23 Sep 2024, 06:15 UTC

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6025 expresstech vulnerability CVSS: 0 11 Jul 2024, 06:15 UTC

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks

CVE-2024-5606 expresstech vulnerability CVSS: 0 02 Jul 2024, 06:15 UTC

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role

CVE-2023-51507 expresstech vulnerability CVSS: 0 14 Jun 2024, 02:15 UTC

Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.

CVE-2024-3592 expresstech vulnerability CVSS: 0 07 Jun 2024, 06:15 UTC

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-26524 expresstech vulnerability CVSS: 0 13 Nov 2023, 00:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions.

CVE-2023-3575 expresstech vulnerability CVSS: 0 07 Aug 2023, 15:15 UTC

The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0292 expresstech vulnerability CVSS: 0 09 Jun 2023, 06:15 UTC

The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary media files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-0291 expresstech vulnerability CVSS: 0 09 Jun 2023, 06:15 UTC

The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.

CVE-2022-46862 expresstech vulnerability CVSS: 0 14 Feb 2023, 12:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions.

CVE-2022-4033 expresstech vulnerability CVSS: 0 29 Nov 2022, 21:15 UTC

The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers to inject content other than the specified value (i.e. a number, file path, etc..). This makes it possible attackers to submit values other than the intended input type.

CVE-2022-4032 expresstech vulnerability CVSS: 0 29 Nov 2022, 21:15 UTC

The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject iFrames in pages that will execute whenever a user accesses an injected page.

CVE-2022-42883 expresstech vulnerability CVSS: 0 18 Nov 2022, 23:15 UTC

Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress.

CVE-2022-40698 expresstech vulnerability CVSS: 0 18 Nov 2022, 23:15 UTC

Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

CVE-2022-41652 expresstech vulnerability CVSS: 0 18 Nov 2022, 19:15 UTC

Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

CVE-2021-36905 expresstech vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress.

CVE-2021-36906 expresstech vulnerability CVSS: 0 03 Nov 2022, 20:15 UTC

Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.

CVE-2021-36898 expresstech vulnerability CVSS: 0 28 Oct 2022, 18:15 UTC

Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.

CVE-2021-36864 expresstech vulnerability CVSS: 0 28 Oct 2022, 18:15 UTC

Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.

CVE-2021-36863 expresstech vulnerability CVSS: 0 28 Oct 2022, 16:15 UTC

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.

CVE-2022-25602 expresstech vulnerability CVSS: 6.5 18 Mar 2022, 18:15 UTC

Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).

CVE-2022-0182 expresstech vulnerability CVSS: 3.5 17 Jan 2022, 10:15 UTC

Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.

CVE-2022-0181 expresstech vulnerability CVSS: 4.3 17 Jan 2022, 10:15 UTC

Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVE-2022-0180 expresstech vulnerability CVSS: 6.8 17 Jan 2022, 10:15 UTC

Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.

CVE-2021-24691 expresstech vulnerability CVSS: 3.5 11 Oct 2021, 11:15 UTC

The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-20792 expresstech vulnerability CVSS: 4.3 18 Aug 2021, 06:15 UTC

Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.

CVE-2021-24368 expresstech vulnerability CVSS: 4.3 20 Jun 2021, 13:15 UTC

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link

CVE-2021-24221 expresstech vulnerability CVSS: 6.5 12 Apr 2021, 14:15 UTC

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this shortcode in post or pages being author, such user could gain unauthorised access to the DBMS. If the shortcode (without the id attribute) is embed on a public page or post, then unauthenticated users could exploit the injection.

CVE-2021-24162 expresstech vulnerability CVSS: 6.8 05 Apr 2021, 19:15 UTC

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.

CVE-2021-24161 expresstech vulnerability CVSS: 6.8 05 Apr 2021, 19:15 UTC

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.

CVE-2021-24160 expresstech vulnerability CVSS: 6.5 05 Apr 2021, 19:15 UTC

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

CVE-2020-35951 expresstech vulnerability CVSS: 6.4 01 Jan 2021, 04:15 UTC

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).

CVE-2020-35949 expresstech vulnerability CVSS: 7.5 01 Jan 2021, 04:15 UTC

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload, and thus the attacker could use text/plain for a .php file.

CVE-2016-11085 expresstech vulnerability CVSS: 4.3 16 Aug 2020, 18:15 UTC

php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.

CVE-2019-17599 expresstech vulnerability CVSS: 4.3 13 Dec 2019, 14:15 UTC

The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.

CVE-2017-18513 expresstech vulnerability CVSS: 6.8 14 Aug 2019, 16:15 UTC

The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.