← WordPress Vulnerabilities
WordPress security by component

Quiz and Survey Master (QSM)

Quiz and Survey Master (QSM) is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2025; the highest CVE/CNA score is 10.

Plugin slug: quiz-and-survey-master

CVE-2024-10679: Quiz and Survey Master (QSM): Cross-site scripting

Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedMar 25, 2025
Safe version guidanceSee mitigation notes
Safe version
Mar 25, 2025 CVE-2024-10679
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Sep 23, 2024 CVE-2024-8758
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Aug 26, 2024 CVE-2024-6879
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.7
NVDPending
Aug 03, 2024 CVE-2024-6390
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Jul 11, 2024 CVE-2024-6025
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jul 02, 2024 CVE-2024-5606
Quiz and Survey Master (QSM): SQL injection
Quiz and Survey Master (QSM) is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Jul 01, 2024 CVE-2024-4934
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVDPending
Jun 07, 2024 CVE-2024-3592
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for: SQL injection
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for is affected by SQL injection. Exploitation requires at least contributor-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.9
NVD6.5
Aug 07, 2023 CVE-2023-3575
Quiz And Survey Master: Cross-site scripting
Quiz And Survey Master is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Nov 29, 2022 CVE-2022-4033
Quiz and Survey Master: A security weakness
Quiz and Survey Master is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Nov 29, 2022 CVE-2022-4032
Quiz and Survey Master: A security weakness
Quiz and Survey Master is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD6.1
Oct 11, 2021 CVE-2021-24691
Quiz And Survey Master: Cross-site scripting
Quiz And Survey Master is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jun 20, 2021 CVE-2021-24368
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin: Cross-site scripting
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 12, 2021 CVE-2021-24221
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for: SQL injection
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Jan 01, 2021 CVE-2020-35951
Quiz And Survey Master: Arbitrary file deletion
Quiz And Survey Master is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable.
See mitigation notes
CVE9.9
NVD9.9
Jan 01, 2021 CVE-2020-35949
Quiz And Survey Master: Code execution
Quiz And Survey Master is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE10.0
NVD9.8
Aug 16, 2020 CVE-2016-11085
Quiz And Survey Master: Cross-site scripting
Quiz And Survey Master is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD6.5