Vulnerability index

Browse CVEs

67 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Limesurvey MEDIUM 6.1
CVE-2025-63238

A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInst…

Fix: 6.15.12+
Fix from $1,600 2026-04-09
Limesurvey MEDIUM 6.1
CVE-2025-70797

Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] …

Patch available
Fix from $1,600 2026-04-09
Limesurvey CRITICAL 9.8
CVE-2025-56422

A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.

Fix: after 6.14.3
Fix from $2,300 2026-03-10
Limesurvey HIGH 7.5
CVE-2025-56421

SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.

Fix: after 6.15.3
Fix from $1,950 2026-03-10
Limesurvey MEDIUM 5.4
CVE-2020-36993

LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can in…

Fix: after 4.3.10
Fix from $1,600 2026-01-28
Limesurvey HIGH 7.5
CVE-2025-41074

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploite…

Mitigation only
Fix from $1,950 2025-11-20
Limesurvey HIGH 7.5
CVE-2025-41075

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited …

Mitigation only
Fix from $1,950 2025-11-20
Limesurvey MEDIUM 6.5
CVE-2025-41076

In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displ…

Mitigation only
Fix from $1,600 2025-11-20
Limesurvey CRITICAL 9.8
CVE-2025-41375

SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via '…

Fix: 3.0.0+
Fix from $2,300 2025-08-01
Limesurvey MEDIUM 5.3
CVE-2025-41376

CRLF Injection vulnerability in Limesurvey v2.65.1+170522.  This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and per…

Fix: 3.0.0+
Fix from $1,600 2025-08-01
Limesurvey MEDIUM 6.1
CVE-2024-28709

Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the …

Fix: 6.5.12+
Fix from $1,600 2024-10-07
Limesurvey MEDIUM 6.1
CVE-2024-28710

Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validatio…

Fix: 6.5.0+
Fix from $1,600 2024-10-07
Limesurvey HIGH 8.8
CVE-2024-42902

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload i…

Fix: after 6.6.2
Fix from $1,950 2024-09-03
Limesurvey MEDIUM 6.5
CVE-2024-42903

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted…

Fix: after 6.6.1
Fix from $1,600 2024-09-03
Limesurvey CRITICAL 9.8
CVE-2024-6933

A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file…

Fix: 6.6.2+
Fix from $2,300 2024-07-21
Limesurvey HIGH 8.8
CVE-2024-39063

Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests…

Fix: after 6.5.12
Fix from $1,950 2024-07-09
Limesurvey MEDIUM 6.1
CVE-2024-24506

Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code …

No fix yet
Fix from $1,600 2024-04-03
Limesurvey MEDIUM 5.4
CVE-2023-44796

Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted scri…

Fix: 6.2.9+
Fix from $1,600 2023-11-18
Limesurvey CRITICAL 9.8
CVE-2022-48008

An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $2,300 2023-01-27
Limesurvey MEDIUM 5.4
CVE-2022-48010

LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rende…

No fix yet
Fix from $1,600 2023-01-27
Limesurvey HIGH 7.2
CVE-2022-43279

LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.

Patch available
Fix from $1,950 2022-11-15
Limesurvey MEDIUM 6.1
CVE-2022-29710

A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or H…

Fix: after 5.3.9
Fix from $1,600 2022-05-25
Limesurvey HIGH 8.8
CVE-2021-44967EPSS 14%

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious…

No fix yet
Fix from $1,950 2022-02-24
Limesurvey MEDIUM 6.1
CVE-2018-10228

Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbi…

Mitigation only
Fix from $1,600 2021-12-14
Limesurvey MEDIUM 6.1
CVE-2021-42112

The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploade…

Fix: after 3.27.18
Fix from $1,600 2021-10-08
Limesurvey MEDIUM 6.1
CVE-2020-22607

Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/Permis…

Patch available
Fix from $1,600 2021-06-28
Limesurvey MEDIUM 5.4
CVE-2020-23710

Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.

Patch available
Fix from $1,600 2021-06-28
Limesurvey CRITICAL 9.8
CVE-2019-25019

LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.

Fix: 3.19.0+
Fix from $2,300 2021-02-14
Limesurvey MEDIUM 5.4
CVE-2020-25797

LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey partic…

Patch available
Fix from $1,600 2020-12-31
Limesurvey MEDIUM 5.4
CVE-2020-25799

LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an…

Patch available
Fix from $1,600 2020-12-31