CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_ht...Show more |
1Mtouch Quiz Project 1Mtouch Quiz Nov 21, 2024 Sep 20, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name. |
1Mtouch Quiz Project 1Mtouch Quiz Nov 21, 2024 Sep 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS. |
1Mtouch Quiz Project 1Mtouch Quiz Nov 21, 2024 Sep 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF. |
1Mtouch Quiz Project 1Mtouch Quiz Nov 21, 2024 Sep 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation. |
Multiple cross-site scripting (XSS) vulnerabilities in question.php in the mTouch Quiz before 3.0.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the quiz parameter to wp-admin/edit.php. |
SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the quiz parameter to wp-admin/edit.php. |