CVE Tools

Quiz and Survey Master (Qsm) – Easy Quiz and Survey Maker

13 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Quiz and Survey Master (Qsm) – Easy Quiz and Survey Maker, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Quiz and Survey Master (Qsm) – Easy Quiz and Survey Maker CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Quiz and Survey Master (Qsm) – Easy Quiz and Survey Maker CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-013
2026-020
2026-031
2026-041
2026-050
2026-062
2026-071
2026-080
2026-090

Severity

How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical18%
  • High215%
  • Medium1077%

Latest CVEs

The 13 most recently published vulnerabilities affecting Quiz and Survey Master (Qsm) – Easy Quiz and Survey Maker.

  1. CVE-2026-9230Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure4.3
  2. CVE-2026-9233Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action4.3
  3. CVE-2026-6448Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters4.9
  4. CVE-2026-5797Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields5.3
  5. CVE-2026-2412Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter6.5
  6. CVE-2025-9318Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter6.5
  7. CVE-2025-9637Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads6.5
  8. CVE-2025-9294Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion4.3
  9. CVE-2024-3592Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection9.9
  10. CVE-2023-0292Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletion5.4
  11. CVE-2023-0291Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletion7.2
  12. CVE-2022-4033Quiz and Survey Master <= 8.0.4 - Improper Input Validation5.3
  13. CVE-2022-4032Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answer7.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store