cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forhd-quiz hd-quiz

Direction: ascending
Jun 07, 2024

HD Quiz # CVE-2024-22161

CVE, Research URL

CVE-2024-22161

Application

HD Quiz

Date
Jan 31, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harmonic Design HD Quiz allows Stored XSS.This issue affects HD Quiz: from n/a through 1.8.11.
Affected versions
Min -, max -.
Status
vulnerable

HD Quiz # CVE-2021-24571

CVE, Research URL

CVE-2021-24571

Application

HD Quiz

Date
Aug 23, 2021
Research Description
The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues
Affected versions
Min -, max -.
Status
vulnerable
May 17, 2025

HD Quiz # CVE-2024-13383

CVE, Research URL

CVE-2024-13383

Application

HD Quiz

Date
May 16, 2025
Research Description
The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable