Harmonicdesign maintains a focused product portfolio centered on its HD Quiz application, a web-based assessment tool where the durable vulnerability signal centers on cross-site scripting issues arising from improper input neutralization in web page generation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Harmonicdesign over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13422MEDIUM The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_no | Jun 27, 2026 | 4.3 | 26 | NO | NO |
CVE-2026-24544MEDIUM Missing Authorization vulnerability in Harmonic Design HD Quiz hd-quiz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz: from n/a | Jan 23, 2026 | 4.3 | 20 | NO | NO |
CVE-2021-24571MEDIUM The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Sc | Aug 23, 2021 | 5.4 | 18 | NO | NO |
CVE-2024-22161MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harmonic Design HD Quiz allows Stored XSS.This issue affects HD Quiz: from n/a | Jan 31, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-13383MEDIUM The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scrip | May 15, 2025 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Harmonicdesign.
Media articles that mention a CVE ID that affects a product developed by Harmonicdesign — matched by CVE ID, not by vendor name.