CVE Tools

Expresstech

19 CVEs tracked since 2021. Since Jan 2021, none of them reached CISA KEV.

Expresstech CVEs per month

Jan 2021 to Nov 2022. Point at a month, or focus the strip and use the arrow keys.
Expresstech CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0120
2021-02null or fewer
2021-03null or fewer
2021-0440
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-0130
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-1030
2022-1170

Products

The products that kept showing up in Expresstech's monthly top three, with their CVEs summed over those months.

  1. Quiz and Survey Master154 months
  2. Quiz and Survey Master (WordPress Plugin)82 months
  3. Responsive Menu31 month
  4. Responsive Menu – Create Mobile-friendly Menu31 month
  5. Responsive Menu Pro31 month
  6. Quiz and Survey Master (Qsm) – Easy Quiz and Survey Maker21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Expresstech.

  1. CVE-2026-15963Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option6.5
  2. CVE-2026-11780Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter6.4
  3. CVE-2026-13767Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter6.5
  4. CVE-2026-9230Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure4.3
  5. CVE-2026-9233Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action4.3
  6. CVE-2026-48867WordPress Quiz And Survey Master plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability7.1
  7. CVE-2026-40787WordPress Quiz And Survey Master plugin <= 11.0.0 - Cross Site Scripting (XSS) vulnerability7.1
  8. CVE-2026-6448Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters4.9
  9. CVE-2026-5797Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields5.3
  10. CVE-2026-2412Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter6.5
  11. CVE-2025-9318Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter6.5
  12. CVE-2025-9637Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads6.5
  13. CVE-2025-9294Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion4.3
  14. CVE-2024-10679Quiz and Survey Master (QSM) < 9.2.1 - Author+ Stored XSS6.1
  15. CVE-2023-37984WordPress Quiz And Survey Master plugin <= 8.1.10 - Broken Access Control vulnerability4.3

The record

Peak rank
#98 in Nov 2022
Busiest month shown
Nov 2022, 7 CVEs
Months with a KEV entry
0 since Jan 2021
Monthly snapshots
5 since 2021
Expresstech's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store