Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Chained Quiz — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Chained Quiz, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration vulnerabilities associated with the Chained Quiz product developed by its vendor. It aggregates security flaw data to provide a comprehensive view of the software's risk profile over time. The content includes a collection of identified vulnerabilities ranging from input validation errors to authentication bypasses, covering reports disclosed within the last five years. Here, users can track the vendor’s security advisories to understand how they respond to emerging threats and remediate specific issues in their releases. Readers can also gain a deeper understanding of specific weakness classes by examining how they manifest within the context of this quiz application, helping to identify recurring patterns in code quality or design flaws. Additionally, the history of vulnerabilities affecting Chained Quiz serves as a resource for assessing the long-term stability and security maintenance practices of the product. This information supports developers and security analysts in making informed decisions about deployment, patching, and mitigation strategies without relying on external marketing claims. By centralizing these records, the page aims to facilitate transparency and improve awareness of the technical debt and security posture of the Chained Quiz software ecosystem.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2025-10493 Chained Quiz <= 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie CWE-639 5.3 Medium2025-09-18
CVE-2025-24701 WordPress Chained Quiz Plugin <= 1.3.2.9 - Server Side Request Forgery (SSRF) vulnerability CWE-918 4.4 Medium2025-01-24
CVE-2024-37921 WordPress Chained Quiz plugin <= 1.3.2.8 - Broken Access Control vulnerability CWE-862 5.3 Medium2024-11-01
CVE-2024-37446 WordPress Chained Quiz plugin <= 1.3.2.8 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium2024-07-21
CVE-2023-25027 WordPress Chained Quiz Plugin <= 1.3.2.5 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium2023-04-07
CVE-2022-4216 Chained Quiz <= 1.3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Facebook App ID CWE-79 5.5 Medium2022-12-02
CVE-2022-4217 Chained Quiz <= 1.3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Mailchimp API Key CWE-79 5.5 Medium2022-12-02
CVE-2022-4212 Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via ipf CWE-79 6.1 Medium2022-12-02
CVE-2022-4211 Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via emailf CWE-79 6.1 Medium2022-12-02
CVE-2022-4210 Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via dnf CWE-79 6.1 Medium2022-12-02
CVE-2022-4209 Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via pointsf CWE-79 6.1 Medium2022-12-02
CVE-2022-4208 Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via datef CWE-79 6.1 Medium2022-12-02
CVE-2022-4213 Chained Quiz <= 1.3.2.2 - Reflected Cross-Site Scripting via dn CWE-79 6.1 Medium2022-12-02
CVE-2022-4214 Chained Quiz <= 1.3.2.3 - Reflected Cross-Site Scripting via ip CWE-79 6.1 Medium2022-12-02
CVE-2022-4215 Chained Quiz <= 1.3.2.3 - Reflected Cross-Site Scripting via date CWE-79 6.1 Medium2022-12-02
CVE-2022-4220 Chained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Question Deletion CWE-352 5.4 Medium2022-12-02
CVE-2022-4219 Chained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Submitted Response Deletion CWE-352 5.4 Medium2022-12-02
CVE-2022-4218 Chained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Arbitrary Quiz Deletion and Copying CWE-352 5.4 Medium2022-12-02
CVE-2021-24690 Chained Quiz < 1.2.7.2 - Authenticated Stored Cross Site Scripting CWE-79 5.4 -2021-10-11

All 19 known CVE vulnerabilities affecting Chained Quiz with full Chinese analysis, references, and POCs where available.