vciy

CVEs we hold for Expresstech

Records whose assigning authority named Expresstech as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9233Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification…expresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2026-9230Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz…expresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2026-65454WordPress Quiz And Survey Master plugin <= 11.2.0 - SQL Injection vulnerabilityExpressTech Systems Quiz And Survey Master
CVE-2026-6448Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parametersexpresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2026-62140WordPress Quiz And Survey Master plugin <= 11.2.5 - Insecure Direct Object References (IDOR) vulnerabilityExpressTech Systems Quiz And Survey Master
CVE-2026-5797Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result…expresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2026-48867WordPress Quiz And Survey Master plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerabilityExpressTech Quiz And Survey Master
CVE-2026-40787WordPress Quiz And Survey Master plugin <= 11.0.0 - Cross Site Scripting (XSS) vulnerabilityExpressTech Quiz And Survey Master
CVE-2026-25329WordPress Quiz And Survey Master plugin <= 10.3.4 - Broken Access Control vulnerabilityExpressTech Systems Quiz And Survey Master
CVE-2026-25324WordPress Quiz And Survey Master plugin <= 10.3.4 - Insecure Direct Object References (IDOR) vulnerabilityExpressTech Systems Quiz And Survey Master
CVE-2026-24358WordPress Quiz And Survey Master plugin <= 10.3.3 - Broken Access Control vulnerabilityExpressTech Systems Quiz And Survey Master
CVE-2026-2412Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameterexpresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2026-15963Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Optionexpresstech Quiz and Survey Master (QSM) – Quiz Maker &…
CVE-2026-13767Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameterexpresstech Quiz and Survey Master (QSM) – Quiz Maker &…
CVE-2026-11780Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title'…expresstech Quiz and Survey Master (QSM) – Quiz Maker &…
CVE-2025-9637Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz…expresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2025-9318Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameterexpresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2025-9294Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletionexpresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2025-68838WordPress MemberPress Discord Addon plugin <= 1.1.4 - Reflected Cross Site Scripting (XSS) vulnerabilityexpresstechsoftware MemberPress Discord Addon
CVE-2025-67987WordPress Quiz And Survey Master plugin <= 10.3.1 - SQL Injection vulnerabilityExpressTech Systems Quiz And Survey Master
CVE-2025-63054WordPress Quiz And Survey Master plugin <= 10.3.2 - Broken Access Control vulnerabilityExpressTech Systems Quiz And Survey Master
CVE-2025-55708WordPress Quiz And Survey Master Plugin <= 10.2.4 - SQL Injection VulnerabilityExpressTech Systems Quiz And Survey Master
CVE-2025-32605WordPress MemberPress Discord Addon Plugin <= 1.1.1 - Reflected Cross Site Scripting (XSS) vulnerabilityexpresstechsoftware MemberPress Discord Addon
CVE-2024-44011WordPress WP Ticket Ultra plugin <= 1.0.5 - Local File Inclusion vulnerabilityExpressTech Systems WP Ticket Ultra Help Desk & Support…
CVE-2024-3592Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL…expresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2024-27966WordPress Quiz And Survey Master plugin <= 8.2.2 - Cross Site Scripting (XSS) vulnerabilityExpressTech Quiz And Survey Master
CVE-2023-51521WordPress Quiz And Survey Master plugin <= 8.1.18 - Cross Site Request Forgery (CSRF) vulnerabilityExpressTech Quiz And Survey Master
CVE-2023-51507WordPress Quiz And Survey Master plugin <= 8.1.16 - Broken Access Control vulnerabilityExpressTech Quiz And Survey Master
CVE-2023-47834WordPress Quiz And Survey Master Plugin <= 8.1.13 is vulnerable to Cross Site Scripting (XSS)ExpressTech Quiz And Survey Master
CVE-2023-37984WordPress Quiz And Survey Master plugin <= 8.1.10 - Broken Access Control vulnerabilityExpressTech Quiz And Survey Master
CVE-2023-28787WordPress Quiz And Survey Master plugin <= 8.1.4 - Unauthenticated SQL Injection vulnerabilityExpressTech Quiz And Survey Master
CVE-2023-26524WordPress Quiz And Survey Master Plugin <= 8.0.10 is vulnerable to Cross Site Request Forgery (CSRF)ExpressTech Quiz And Survey Master – Best Quiz, Exam and…
CVE-2023-0292Quiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletionexpresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2023-0291Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletionexpresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2022-46862WordPress Quiz And Survey Master Plugin <= 8.0.7 is vulnerable to Cross Site Request Forgery (CSRF)ExpressTech Quiz And Survey Master – Best Quiz, Exam and…
CVE-2022-42883WordPress Quiz And Survey Master plugin <= 7.3.10 - Sensitive Information Disclosure vulnerabilityExpressTech Quiz And Survey Master (WordPress plugin)
CVE-2022-41652WordPress Quiz And Survey Master plugin <= 7.3.10 - Bypass vulnerabilityExpressTech Quiz And Survey Master (WordPress plugin)
CVE-2022-40698WordPress Quiz And Survey Master plugin <= 7.3.10 - Cross-Site Scripting (XSS) vulnerabilityExpressTech Quiz And Survey Master (WordPress plugin)
CVE-2022-4033Quiz and Survey Master <= 8.0.4 - Improper Input Validationexpresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2022-4032Quiz and Survey Master <= 8.0.4 - Unauthenticated iFrame Injection via Paragraph and Short Answerexpresstech Quiz and Survey Master (QSM) – Easy Quiz and…
CVE-2022-25602WordPress Responsive Menu plugin <= 4.1.7 - Nonce token leak leading to arbitrary file upload, theme deletion, plugin…ExpressTech Responsive Menu (WordPress plugin)
CVE-2022-0182no title heldExpressTech Quiz And Survey Master
CVE-2022-0181no title heldExpressTech Quiz And Survey Master
CVE-2022-0180no title heldExpressTech Quiz And Survey Master
CVE-2021-36906WordPress Quiz And Survey Master plugin <= 7.3.6 - Multiple Insecure direct object references (IDOR) vulnerabilitiesExpressTech Quiz And Survey Master (WordPress plugin)
CVE-2021-36905WordPress Quiz And Survey Master plugin <= 7.3.4 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilitiesExpressTech Quiz And Survey Master (WordPress plugin)
CVE-2021-36898WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. SQL Injection (SQLi) vulnerabilityExpressTech Quiz And Survey Master (WordPress plugin)
CVE-2021-36865WordPress Quiz And Survey Master plugin <= 7.3.4 - Insecure direct object references (IDOR) vulnerabilityExpressTech Quiz And Survey Master (WordPress plugin)
CVE-2021-36864WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. Reflected Cross-Site Scripting (XSS) vulnerabilityExpressTech Quiz And Survey Master (WordPress plugin)
CVE-2021-36863WordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilityExpressTech Quiz And Survey Master (WordPress plugin)
CVE-2021-24368Quiz And Survey Master < 7.1.18 - Reflected Cross-Site Scripting (XSS)ExpressTech Quiz And Survey Master – Best Quiz, Exam and…
CVE-2021-24162Responsive Menu < 4.0.4 - CSRF to Settings UpdateExpressTech Responsive Menu Pro
CVE-2021-24161Responsive Menu < 4.0.4 - CSRF to Arbitrary File UploadExpressTech Responsive Menu Pro
CVE-2021-24160Responsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File UploadExpressTech Responsive Menu Pro
CVE-2021-20792no title heldExpressTech Quiz And Survey Master

55 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.