WordPress security by component
Quiz and Survey Master (QSM)
Plugin description
Quiz and Survey Master creates customizable quizzes and surveys with questions, results, scoring, and response management features.
Quiz and Survey Master (QSM) (quiz-and-survey-master) is a WordPress plugin with 17 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2025; the highest published CVSS base score is 10.
Plugin slug:
quiz-and-survey-masterLatest vulnerability
CVE-2024-10679: Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Mar 25, 2025 |
CVE-2024-10679
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Sep 23, 2024 |
CVE-2024-8758
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Aug 26, 2024 |
CVE-2024-6879
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.7
NVDPending
|
| Aug 03, 2024 |
CVE-2024-6390
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Jul 11, 2024 |
CVE-2024-6025
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jul 02, 2024 |
CVE-2024-5606
Quiz and Survey Master (QSM): SQL injection
Quiz and Survey Master (QSM) is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Jul 01, 2024 |
CVE-2024-4934
Quiz and Survey Master (QSM): Cross-site scripting
Quiz and Survey Master (QSM) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVDPending
|
| Jun 07, 2024 |
CVE-2024-3592
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for: SQL injection
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.9
NVD6.5
|
| Aug 07, 2023 |
CVE-2023-3575
Quiz And Survey Master: Cross-site scripting
Quiz And Survey Master is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Nov 29, 2022 |
CVE-2022-4033
Quiz and Survey Master: A security weakness
Quiz and Survey Master is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Nov 29, 2022 |
CVE-2022-4032
Quiz and Survey Master: A security weakness
Quiz and Survey Master is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Oct 11, 2021 |
CVE-2021-24691
Quiz And Survey Master: Cross-site scripting
Quiz And Survey Master is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Jun 20, 2021 |
CVE-2021-24368
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin: Cross-site scripting
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Apr 12, 2021 |
CVE-2021-24221
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for: SQL injection
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Jan 01, 2021 |
CVE-2020-35951
Quiz And Survey Master: Arbitrary file deletion
Quiz And Survey Master is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable.
|
See mitigation notes |
CVE9.9
NVD9.9
|
| Jan 01, 2021 |
CVE-2020-35949
Quiz And Survey Master: Code execution
Quiz And Survey Master is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE10.0
NVD9.8
|
| Aug 16, 2020 |
CVE-2016-11085
Quiz And Survey Master: Cross-site scripting
Quiz And Survey Master is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.5
|