mtouch_quiz_project CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

mtouch_quiz_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all mtouch_quiz_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk csrf and vendor risk sql injection and related problems; some flaws may lead to vendor impact data exposure, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-2410 The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) [email protected] 4.8 0.21% 2022-08-08 2024-11-21
CVE-2015-9389 The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name. [email protected] 5.4 0.18% 2019-09-20 2024-11-21
CVE-2015-9388 The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS. [email protected] 6.5 0.14% 2019-09-20 2024-11-21
CVE-2015-9387 The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF. [email protected] 6.5 0.15% 2019-09-20 2024-11-21
CVE-2015-9386 The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation. [email protected] 6.1 0.21% 2019-09-20 2024-11-21
CVE-2014-100023 Multiple cross-site scripting (XSS) vulnerabilities in question.php in the mTouch Quiz before 3.0.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the quiz parameter to wp-admin/edit.php. [email protected] 4.3 0.23% 2015-01-13 2026-05-06
CVE-2014-100022 SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the quiz parameter to wp-admin/edit.php. [email protected] 7.5 0.42% 2015-01-13 2026-05-06
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence