ExpressTech kayıtları
expresstech üreticisine ait 43 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %23,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-862 Missing Authorization3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
43 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2020-35951Kavram kanıtı | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress.expresstech · quiz and survey master · CWE-306 | Kritik9,9 | — | %76,3 | 1 Oca 2021 |
41Planlayın | CVE-2020-35949İstismar yok | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress.expresstech · quiz and survey master · CWE-434 | Kritik9,8 | — | %5,1 | 1 Oca 2021 |
39İzleyin | CVE-2022-41652İstismar yok | WordPress Quiz And Survey Master plugin <= 7.3.10 - Bypass vulnerabilityexpresstech · quiz and survey master · CWE-284 | Kritik9,8 | — | %0,7 | 18 Kas 2022 |
37İzleyin | CVE-2021-24160Kavram kanıtı | Responsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File Uploadexpresstech · responsive menu · CWE-434 | Yüksek8,8 | — | %8,2 | 5 Nis 2021 |
37İzleyin | CVE-2023-0291İstismar yok | Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletionexpresstech · quiz and survey master · CWE-862 | Kritik9,1 | — | %2,0 | 9 Haz 2023 |
36İzleyin | CVE-2021-24221İstismar yok | Quiz And Survey Master < 7.1.12 - Authenticated SQL injection via shortcodeexpresstech · quiz and survey master · CWE-89 | Yüksek8,8 | — | %1,9 | 12 Nis 2021 |
35İzleyin | CVE-2022-25602İstismar yok | WordPress Responsive Menu plugin <= 4.1.7 - Nonce token leak leading to arbitrary file upload, theme deletion, plugin settings change vulnerabilityexpresstech · responsive menu · CWE-200 | Yüksek8,8 | — | %1,3 | 18 Mar 2022 |
35İzleyin | CVE-2021-24161İstismar yok | Responsive Menu < 4.0.4 - CSRF to Arbitrary File Uploadexpresstech · responsive menu · CWE-352 | Yüksek8,8 | — | %1,2 | 5 Nis 2021 |
35İzleyin | CVE-2021-24162İstismar yok | Responsive Menu < 4.0.4 - CSRF to Settings Updateexpresstech · responsive menu · CWE-352 | Yüksek8,8 | — | %0,8 | 5 Nis 2021 |
35İzleyin | CVE-2022-0180İstismar yok | Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the autexpresstech · quiz and survey master · CWE-352 | Yüksek8,8 | — | %0,7 | 17 Oca 2022 |
35İzleyin | CVE-2017-18513İstismar yok | The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.expresstech · responsive menu · CWE-352 | Yüksek8,8 | — | %0,6 | 14 Ağu 2019 |
35İzleyin | CVE-2024-5606İstismar yok | Quiz And Survey Master < 9.0.2 - Contributor+ SQLiexpresstech · quiz and survey master · CWE-89 | Yüksek8,8 | — | %0,6 | 2 Tem 2024 |
35İzleyin | CVE-2021-36906İstismar yok | WordPress Quiz And Survey Master plugin <= 7.3.6 - Multiple Insecure direct object references (IDOR) vulnerabilitiesexpresstech · quiz and survey master · CWE-639 | Yüksek8,8 | — | %0,6 | 3 Kas 2022 |
35İzleyin | CVE-2022-46862İstismar yok | WordPress Quiz And Survey Master Plugin <= 8.0.7 is vulnerable to Cross Site Request Forgery (CSRF)expresstech · quiz and survey master · CWE-352 | Yüksek8,8 | — | %0,4 | 14 Şub 2023 |
35İzleyin | CVE-2023-26524İstismar yok | WordPress Quiz And Survey Master Plugin <= 8.0.10 is vulnerable to Cross Site Request Forgery (CSRF)expresstech · quiz and survey master · CWE-352 | Yüksek8,8 | — | %0,3 | 12 Kas 2023 |
32İzleyin | CVE-2023-0292İstismar yok | Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletionexpresstech · quiz and survey master · CWE-352 | Yüksek8,1 | — | %0,8 | 9 Haz 2023 |
30İzleyin | CVE-2022-42883İstismar yok | WordPress Quiz And Survey Master plugin <= 7.3.10 - Sensitive Information Disclosure vulnerabilityexpresstech · quiz and survey master · CWE-200 | Yüksek7,5 | — | %0,7 | 18 Kas 2022 |
28İzleyin | CVE-2021-36898İstismar yok | WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. SQL Injection (SQLi) vulnerabilityexpresstech · quiz and survey master · CWE-89 | Yüksek7,2 | — | %0,9 | 28 Eki 2022 |
26İzleyin | CVE-2016-11085İstismar yok | php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the expresstech · quiz and survey master · CWE-79 | Orta6,5 | — | %1,0 | 16 Ağu 2020 |
26İzleyin | CVE-2024-3592İstismar yok | Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injectionexpresstech · quiz and survey master · CWE-89 | Orta6,5 | — | %0,5 | 7 Haz 2024 |
26İzleyin | CVE-2025-9637İstismar yok | Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uplexpresstech · quiz and survey master · CWE-862 | Orta6,5 | — | %0,3 | 6 Oca 2026 |
26İzleyin | CVE-2025-9318İstismar yok | Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameterexpresstech · quiz and survey master · CWE-89 | Orta6,5 | — | %0,3 | 6 Oca 2026 |
25İzleyin | CVE-2021-20792Kavram kanıtı | Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script viexpresstech · quiz and survey master · CWE-79 | Orta6,1 | — | %3,4 | 18 Ağu 2021 |
24İzleyin | CVE-2019-17599İstismar yok | The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS).expresstech · quiz and survey master · CWE-79 | Orta6,1 | — | %1,7 | 13 Ara 2019 |
24İzleyin | CVE-2022-0181İstismar yok | Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitraexpresstech · quiz and survey master · CWE-79 | Orta6,1 | — | %1,3 | 17 Oca 2022 |
- CVE-2020-3595162Bu hafta
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress.
KritikCVSS 9,9Kavram kanıtıEPSS %76expresstech · quiz and survey master1 Oca 2021
- CVE-2020-3594941Planlayın
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress.
KritikCVSS 9,8İstismar yokEPSS %5expresstech · quiz and survey master1 Oca 2021
- CVE-2022-4165239İzleyin
WordPress Quiz And Survey Master plugin <= 7.3.10 - Bypass vulnerability
KritikCVSS 9,8İstismar yokEPSS %1expresstech · quiz and survey master18 Kas 2022
- CVE-2021-2416037İzleyin
Responsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File Upload
YüksekCVSS 8,8Kavram kanıtıEPSS %8expresstech · responsive menu5 Nis 2021
- CVE-2023-029137İzleyin
Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletion
KritikCVSS 9,1İstismar yokEPSS %2expresstech · quiz and survey master9 Haz 2023
- CVE-2021-2422136İzleyin
Quiz And Survey Master < 7.1.12 - Authenticated SQL injection via shortcode
YüksekCVSS 8,8İstismar yokEPSS %2expresstech · quiz and survey master12 Nis 2021
- CVE-2022-2560235İzleyin
WordPress Responsive Menu plugin <= 4.1.7 - Nonce token leak leading to arbitrary file upload, theme deletion, plugin settings change vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1expresstech · responsive menu18 Mar 2022
- CVE-2021-2416135İzleyin
Responsive Menu < 4.0.4 - CSRF to Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %1expresstech · responsive menu5 Nis 2021
- CVE-2021-2416235İzleyin
Responsive Menu < 4.0.4 - CSRF to Settings Update
YüksekCVSS 8,8İstismar yokEPSS %1expresstech · responsive menu5 Nis 2021
- CVE-2022-018035İzleyin
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the aut
YüksekCVSS 8,8İstismar yokEPSS %1expresstech · quiz and survey master17 Oca 2022
- CVE-2017-1851335İzleyin
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
YüksekCVSS 8,8İstismar yokEPSS %1expresstech · responsive menu14 Ağu 2019
- CVE-2024-560635İzleyin
Quiz And Survey Master < 9.0.2 - Contributor+ SQLi
YüksekCVSS 8,8İstismar yokEPSS %1expresstech · quiz and survey master2 Tem 2024
- CVE-2021-3690635İzleyin
WordPress Quiz And Survey Master plugin <= 7.3.6 - Multiple Insecure direct object references (IDOR) vulnerabilities
YüksekCVSS 8,8İstismar yokEPSS %1expresstech · quiz and survey master3 Kas 2022
- CVE-2022-4686235İzleyin
WordPress Quiz And Survey Master Plugin <= 8.0.7 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0expresstech · quiz and survey master14 Şub 2023
- CVE-2023-2652435İzleyin
WordPress Quiz And Survey Master Plugin <= 8.0.10 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0expresstech · quiz and survey master12 Kas 2023
- CVE-2023-029232İzleyin
Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletion
YüksekCVSS 8,1İstismar yokEPSS %1expresstech · quiz and survey master9 Haz 2023
- CVE-2022-4288330İzleyin
WordPress Quiz And Survey Master plugin <= 7.3.10 - Sensitive Information Disclosure vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1expresstech · quiz and survey master18 Kas 2022
- CVE-2021-3689828İzleyin
WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. SQL Injection (SQLi) vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1expresstech · quiz and survey master28 Eki 2022
- CVE-2016-1108526İzleyin
php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the
OrtaCVSS 6,5İstismar yokEPSS %1expresstech · quiz and survey master16 Ağu 2020
- CVE-2024-359226İzleyin
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection
OrtaCVSS 6,5İstismar yokEPSS %0expresstech · quiz and survey master7 Haz 2024
- CVE-2025-963726İzleyin
Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Upl
OrtaCVSS 6,5İstismar yokEPSS %0expresstech · quiz and survey master6 Oca 2026
- CVE-2025-931826İzleyin
Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter
OrtaCVSS 6,5İstismar yokEPSS %0expresstech · quiz and survey master6 Oca 2026
- CVE-2021-2079225İzleyin
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script vi
OrtaCVSS 6,1Kavram kanıtıEPSS %3expresstech · quiz and survey master18 Ağu 2021
- CVE-2019-1759924İzleyin
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS).
OrtaCVSS 6,1İstismar yokEPSS %2expresstech · quiz and survey master13 Ara 2019
- CVE-2022-018124İzleyin
Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitra
OrtaCVSS 6,1İstismar yokEPSS %1expresstech · quiz and survey master17 Oca 2022