Expresstech
19 CVEs tracked since 2021. Since Jan 2021, none of them reached CISA KEV.
Expresstech CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-01 | 2 | 0 |
| 2021-02 | null or fewer | |
| 2021-03 | null or fewer | |
| 2021-04 | 4 | 0 |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | null or fewer | |
| 2021-11 | null or fewer | |
| 2021-12 | null or fewer | |
| 2022-01 | 3 | 0 |
| 2022-02 | null or fewer | |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | null or fewer | |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | 3 | 0 |
| 2022-11 | 7 | 0 |
Products
The products that kept showing up in Expresstech's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Expresstech.
- CVE-2026-15963Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option6.5
- CVE-2026-11780Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter6.4
- CVE-2026-13767Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter6.5
- CVE-2026-9230Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure4.3
- CVE-2026-9233Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action4.3
- CVE-2026-48867WordPress Quiz And Survey Master plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-40787WordPress Quiz And Survey Master plugin <= 11.0.0 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-6448Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters4.9
- CVE-2026-5797Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields5.3
- CVE-2026-2412Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter6.5
- CVE-2025-9318Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter6.5
- CVE-2025-9637Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads6.5
- CVE-2025-9294Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion4.3
- CVE-2024-10679Quiz and Survey Master (QSM) < 9.2.1 - Author+ Stored XSS6.1
- CVE-2023-37984WordPress Quiz And Survey Master plugin <= 8.1.10 - Broken Access Control vulnerability4.3
The record
- Peak rank
- #98 in Nov 2022
- Busiest month shown
- Nov 2022, 7 CVEs
- Months with a KEV entry
- 0 since Jan 2021
- Monthly snapshots
- 5 since 2021