CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-97289 HIGH

WordPress Quiz And Survey Master plugin <= 11.2.6 - Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.25% Sep 30, 2026
CVE-2026-62140 MEDIUM

WordPress Quiz And Survey Master plugin <= 11.2.5 - Insecure Direct Object References (IDOR) vulnerability

CVSS 5.3 EPSS 0.31% Sep 11, 2026
CVE-2026-15963 MEDIUM

Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option

CVSS 6.5 EPSS 0.45% Aug 16, 2026
CVE-2026-11780 MEDIUM

Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter

CVSS 6.4 EPSS 0.42% Aug 16, 2026
CVE-2026-65454 HIGH

WordPress Quiz And Survey Master plugin <= 11.2.0 - SQL Injection vulnerability

CVSS 8.5 EPSS 0.36% Jul 23, 2026
CVE-2026-13767 MEDIUM

Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter

CVSS 6.5 EPSS 0.41% Jul 16, 2026
CVE-2026-9230 MEDIUM

Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce f…

CVSS 4.3 EPSS 0.49% Jul 3, 2026
CVE-2026-9233 MEDIUM

Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action

CVSS 4.3 EPSS 0.47% Jun 27, 2026
CVE-2026-48867 HIGH

WordPress Quiz And Survey Master plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.25% Jun 15, 2026
CVE-2026-40787 HIGH

WordPress Quiz And Survey Master plugin <= 11.0.0 - Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.25% Jun 15, 2026
CVE-2026-6448 MEDIUM

Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters

CVSS 4.9 EPSS 0.60% Jun 5, 2026
CVE-2026-5797 MEDIUM

Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields

CVSS 5.3 EPSS 0.67% Apr 17, 2026
CVE-2026-2412 MEDIUM

Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter

CVSS 6.5 EPSS 0.32% Mar 23, 2026
CVE-2025-67987 HIGH

WordPress Quiz And Survey Master plugin <= 10.3.1 - SQL Injection vulnerability

CVSS 8.5 EPSS 0.27% Feb 20, 2026
CVE-2026-25329 MEDIUM

WordPress Quiz And Survey Master plugin <= 10.3.4 - Broken Access Control vulnerability

CVSS 4.3 EPSS 0.19% Feb 19, 2026
CVE-2026-25324 MEDIUM

WordPress Quiz And Survey Master plugin <= 10.3.4 - Insecure Direct Object References (IDOR) vulnerability

CVSS 5.3 EPSS 0.33% Feb 19, 2026
CVE-2026-24358 MEDIUM

WordPress Quiz And Survey Master plugin <= 10.3.3 - Broken Access Control vulnerability

CVSS 4.3 EPSS 0.18% Jan 22, 2026
CVE-2025-68838 HIGH

WordPress MemberPress Discord Addon plugin <= 1.1.4 - Reflected Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.26% Jan 22, 2026
CVE-2025-9318 MEDIUM

Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter

CVSS 6.5 EPSS 0.25% Jan 6, 2026
CVE-2025-9637 MEDIUM

Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Up…

CVSS 6.5 EPSS 0.26% Jan 6, 2026
CVE-2025-9294 MEDIUM

Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion

CVSS 4.3 EPSS 0.22% Jan 6, 2026
CVE-2025-63054 MEDIUM

WordPress Quiz And Survey Master plugin <= 10.3.2 - Broken Access Control vulnerability

CVSS 5.3 EPSS 0.30% Dec 9, 2025
CVE-2025-49401 CRITICAL

WordPress smart SEO Plugin <= 4.0 - Privilege Escalation Vulnerability

CVSS 9.8 EPSS 0.44% Sep 5, 2025
CVE-2025-55708 HIGH

WordPress Quiz And Survey Master Plugin <= 10.2.4 - SQL Injection Vulnerability

CVSS 8.5 EPSS 0.27% Aug 14, 2025
CVE-2025-32605 HIGH

WordPress MemberPress Discord Addon Plugin <= 1.1.1 - Reflected Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.29% Apr 17, 2025

Showing 1 to 25 CVEs · page 1 (more available)