Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Expresstech

First CVE: Aug 14, 2019Active for: 7 yearsTotal CVEs: 50
42.1
VTI Score
High

Expresstech maintains a modest portfolio of WordPress plugins focused on interactive content and navigation functionality, notably Quiz and Survey Master and Responsive Menu, which serve a distributed user base across numerous WordPress installations. Despite the narrow product scope, these plugins occupy a prominent position in the WordPress ecosystem due to their widespread adoption and deep integration into site architecture. The recurring vulnerability patterns center on web-application input-handling and authorization issues—cross-site scripting, SQL injection, CSRF, missing authorization checks, and unrestricted file uploads—which are characteristic of plugin-level exposure in a content-management environment where trust boundaries between administrator and user input are frequently breached. A meaningful share of the vendor's disclosures reach serious severity, reflecting the potential for authenticated and unauthenticated attackers to compromise site integrity and user data. Defenders should treat Expresstech plugin updates as part of routine WordPress maintenance and monitor for upstream patches, particularly on internet-facing sites; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
50
Total CVEs
More Total CVEs than 98% of tracked vendors
3.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Expresstech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2019
6 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35951CRITICAL
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effective
Jan 1, 20219.980NOYES
CVE-2023-28787CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master:
Mar 26, 20249.339NOYES
CVE-2022-41652CRITICAL
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
Nov 18, 20229.831NONO
CVE-2021-20792MEDIUM
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
Aug 18, 20216.131NOYES
CVE-2020-35949CRITICAL
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve rem
Jan 1, 20219.830NONO
CVE-2023-0291CRITICAL
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJA
Jun 9, 20239.129NONO
CVE-2021-24160HIGH
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/
Apr 5, 20218.829NONO
CVE-2026-40787HIGH
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.
Jun 15, 20267.128NONO
CVE-2021-36906HIGH
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.
Nov 3, 20228.828NONO
CVE-2022-0180HIGH
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduc
Jan 17, 20228.828NONO
View all 50 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products50 CVEs
58%
32%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network50 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low50 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (38.0%)
Unknown0 (0.0%)
Required31 (62.0%)
Privileges Required
Low17 (34.0%)
High5 (10.0%)
None28 (56.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
6.0% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Expresstech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Expresstech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Expresstech's Products

View all 5 CNAs →

Top CWEs