Pricing
Case studies
Login
Start trial
Quiz And Survey Master
ExpressTech Systems
Developer
11.0.0
Latest version
40,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
50 patched
13 Mitigation rules
Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter vulnerability
<= 10.3.5
6 days ago
Broken Access Control vulnerability
<= 10.3.4
05/02/2026
Insecure Direct Object References (IDOR) vulnerability
<= 10.3.4
01/02/2026
Contributor+ SQLi vulnerability
< 9.0.2
29/01/2026
SQL Injection vulnerability
<= 10.3.1
28/01/2026
Broken Access Control vulnerability
<= 10.3.3
08/01/2026
Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads vulnerability
<= 10.3.1
06/01/2026
Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion vulnerability
<= 10.3.1
05/01/2026
Broken Access Control vulnerability
<= 10.3.2
30/11/2025
PHP Object Injection Vulnerability
<= 10.2.5
03/09/2025
Template Creation via CSRF vulnerability
< 10.2.3
14/08/2025
SQL Injection Vulnerability
<= 10.2.4
14/08/2025
Author+ Stored XSS vulnerability
< 9.2.1
25/03/2025
Author+ Stored XSS vulnerability
< 9.1.3
23/09/2024
Contributor+ Stored XSS vulnerability
< 9.1.1
26/08/2024
Contributor+ Stored XSS vulnerability
< 9.1.0
05/08/2024
Contributor+ Stored XSS vulnerability
< 9.0.5
11/07/2024
Contributor+ Stored XSS vulnerability
< 9.0.2
01/07/2024
Authenticated (Contributor+) SQL Injection vulnerability
<= 9.0.1
07/06/2024
Cross Site Scripting (XSS) vulnerability
<= 8.2.2
13/03/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 8.1.18
27/12/2023
Broken Access Control vulnerability
<= 8.1.16
27/12/2023
Cross Site Scripting (XSS) vulnerability
<= 8.1.13
16/11/2023
Cross-Site Request Forgery via 'display_results' vulnerability
<= 8.1.15
13/09/2023
Contributor+ Stored XSS vulnerability
< 8.1.11
27/07/2023
Broken Access Control vulnerability
<= 8.1.10
17/07/2023
Unauthenticated SQL Injection vulnerability
<= 8.1.4
16/04/2023
Cross Site Request Forgery (CSRF) vulnerability
<= 8.0.10
28/02/2023
Unauthenticated Arbitrary Media Deletion vulnerability
<= 8.0.8
17/02/2023
Cross Site Request Forgery (CSRF)
<= 8.0.7
12/02/2023
Unauth. iFrame Injection vulnerability via Paragraph and Short Answer
<= 8.0.4
29/11/2022
Improper Input Validation vulnerability
<= 8.0.4
29/11/2022
Bypass vulnerability
<= 7.3.10
21/10/2022
Sensitive Information Disclosure vulnerability
<= 7.3.10
21/10/2022
Cross-Site Scripting (XSS) vulnerability
<= 7.3.10
21/10/2022
Multiple Insecure direct object references (IDOR) vulnerabilities
<= 7.3.6
21/10/2022
Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilities
<= 7.3.4
21/10/2022
Auth. SQL Injection (SQLi) vulnerability
<= 7.3.4
21/10/2022
Auth. Reflected Cross-Site Scripting (XSS) vulnerability
<= 7.3.4
21/10/2022
Auth. Stored Cross-Site Scripting (XSS) vulnerability
<= 7.3.4
21/10/2022
Insecure direct object references (IDOR) vulnerability
<= 7.3.4
29/09/2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 7.3.1
13/09/2021
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 7.1.18
03/06/2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 7.1.17
31/05/2021
Authenticated SQL injection (SQLi) vulnerability
<= 7.1.13
26/03/2021
Unauthenticated Arbitrary File Upload vulnerability
<= 7.0.1
29/08/2020
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
<= 6.3.4
15/12/2019
Authenticated Cross-Site Scripting (XSS) vulnerability
<= 6.2.1
12/03/2019
Multiple Vulnerabilities
<= 4.7.8
15/12/2016
Blind SQL Injection
<= 4.4.2
16/07/2015