VulnSea

ExpressTech has 4 CVEs on record. 1 was published in the last 90 days. The busiest recent month was January 2026 with 3. The median CVSS is 6.5 (medium). Most affected products: quiz_and_survey_master (3), quiz-master-next (1).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
1 prev 0

Products

  • quiz_and_survey_master 3
  • quiz-master-next 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

ExpressTech vulnerabilities

CVEs affecting ExpressTech, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-104391Medium· 6.5
today

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 11.2.7.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 11.2.7.

▾ SunlitExpressTech · quiz-master-nextvia NVD
CVE-2025-9637Medium· 6.5
9mo ago

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, a…

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, a…

▾ Sunlitexpresstech · quiz_and_survey_masterEPSS 0.27%via NVD
CVE-2025-9318Medium· 6.5
9mo ago

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the …

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the …

▾ Sunlitexpresstech · quiz_and_survey_masterEPSS 0.26%via NVD
CVE-2025-9294Medium· 4.3
9mo ago

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and includ…

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and includ…

▾ Sunlitexpresstech · quiz_and_survey_masterEPSS 0.22%via NVD
ExpressTech vulnerabilities (CVEs) · VulnSea