Mtouch Quiz Project operates a quiz application framework that is modestly represented in the vulnerability landscape, with its exposure concentrating in the core Mtouch Quiz product and centering on application-layer input-handling weaknesses. The recurring vulnerability classes—cross-site scripting, cross-site request forgery, and SQL injection—reflect the web-application context and are characteristic of insufficient input sanitization and request validation in form-driven systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mtouch Quiz Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-100022HIGH SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the quiz parameter to wp-adm | Jan 13, 2015 | 7.5 | 24 | NO | NO |
CVE-2015-9387MEDIUM The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF. | Sep 20, 2019 | 6.5 | 22 | NO | NO |
CVE-2022-2410MEDIUM The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | Aug 8, 2022 | 4.8 | 19 | NO | NO |
CVE-2015-9388MEDIUM The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS. | Sep 20, 2019 | 6.5 | 17 | NO | NO |
CVE-2015-9386MEDIUM The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation. | Sep 20, 2019 | 6.1 | 17 | NO | NO |
CVE-2014-100023MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in question.php in the mTouch Quiz before 3.0.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via | Jan 13, 2015 | 4.3 | 17 | NO | NO |
CVE-2015-9389MEDIUM The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name. | Sep 20, 2019 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mtouch Quiz Project.
Media articles that mention a CVE ID that affects a product developed by Mtouch Quiz Project — matched by CVE ID, not by vendor name.