Quiz and Survey Master (Qsm) – Easy Quiz and Survey Maker
13 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Quiz and Survey Master (Qsm) – Easy Quiz and Survey Maker, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Quiz and Survey Master (Qsm) – Easy Quiz and Survey Maker CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 3 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 2 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High2
- Medium10
Latest CVEs
The 13 most recently published vulnerabilities affecting Quiz and Survey Master (Qsm) – Easy Quiz and Survey Maker.
- CVE-2026-9230Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure4.3
- CVE-2026-9233Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action4.3
- CVE-2026-6448Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters4.9
- CVE-2026-5797Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields5.3
- CVE-2026-2412Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter6.5
- CVE-2025-9318Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter6.5
- CVE-2025-9637Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads6.5
- CVE-2025-9294Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion4.3
- CVE-2024-3592Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection9.9
- CVE-2023-0292Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletion5.4
- CVE-2023-0291Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletion7.2
- CVE-2022-4033Quiz and Survey Master <= 8.0.4 - Improper Input Validation5.3
- CVE-2022-4032Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answer7.2
Product grouping is registry-driven, with AI assist and human review. How it works