CVE-2026-11780

Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 642 live websites that are affected by CVE-2026-11780.

Run a Free Instant Scan




Affected Software

Product  Quiz Master Next
Category Wordpress Plugins
Vulnerable Domains642 live websites (88% of Quiz Master Next install base)
Vulnerable Versions
  • from 0 through 11.2.1
Vulnerable Versions Count58 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 16, 2026
  • Updated - Aug 18, 2026

Credits

  • Jonah Burgess (CryptoCat) (finder)

Website Distribution by Country

Number of websites using CVE-2026-11780
United States171 websites



Germany67 websites
Russia42 websites
France34 websites
GB28 websites
Netherlands23 websites
Spain22 websites
Japan21 websites
Italy20 websites
Canada15 websites

Website Distribution by TLD

Number of websites using CVE-2026-11780
.com243 websites
.org37 websites
.ru33 websites
.de33 websites
.nl19 websites
.it17 websites
.co.uk14 websites
.fr13 websites
.pl12 websites
.com.br11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-11780

Top websites that are affected by CVE-2026-11780. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******************.com United States***,***
*************.com United States***,***
************.de Germany***,***
****************.com United States***,***
************.org United States***,***
****.*******************.com United States***,***
**************.************.***.sg United States***,***
*********************.net United States***,***
*******************.************.***.pl Poland***,***
****.***.***.au Australia***,***
See full domain list

FAQ

CVE-2026-11780 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Quiz Master Next
A total of 642 websites have been identified as vulnerable to CVE-2026-11780, based on global website indexing conducted by WebTechSurvey.
The Quiz Master Next is affected by the CVE-2026-11780 vulnerability.
Quiz Master Next versions up to and including 11.2.1 are vulnerable to CVE-2026-11780.

References