PatchSiren

expresstech CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM expresstech CVE published 2026-07-16

CVE-2026-13767

The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient preparation on the existing SQL query built in qsm_options_questions_tab_content() at lin [truncated]

HIGH ExpressTech CVE published 2026-06-15

CVE-2026-48867

A high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability was discovered in Quiz And Survey Master plugin versions <= 11.1.2. This vulnerability, tracked as CVE-2026-48867, has a CVSS score of 7.1 and is considered HIGH severity. The vulnerability was made public on June 15, 2026.

HIGH ExpressTech CVE published 2026-06-15

CVE-2026-40787

CVE-2026-40787 is a Unauthenticated Cross Site Scripting (XSS) vulnerability affecting Quiz And Survey versions up to 11.0.0. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. It was published on [2026-06-15T21:16:50.943Z](https://www.cve.org/CVERecord?id=CVE-2026-40787) and last modified on [2026-06-15T21:24:32.790Z](https://www.cve.org/CVERecord?id=CVE-2026-40787).