Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-41074 Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploite… Limesurvey Mitigation only Fix from $1,9502025-11-20 HIGH 7.5 CVE-2025-41075 Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited … Limesurvey Mitigation only Fix from $1,9502025-11-20 MEDIUM 6.5 CVE-2025-41076 In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displ… Limesurvey Mitigation only Fix from $1,6002025-11-20 MEDIUM 6.1 CVE-2024-24506 Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code … Limesurvey No fix yet Fix from $1,6002024-04-03 CRITICAL 9.8 CVE-2022-48008 An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file. Limesurvey No fix yet Fix from $2,3002023-01-27 MEDIUM 5.4 CVE-2022-48010 LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rende… Limesurvey No fix yet Fix from $1,6002023-01-27 HIGH 8.8 CVE-2021-44967EPSS 14% A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious… Limesurvey No fix yet Fix from $1,9502022-02-24 MEDIUM 6.1 CVE-2018-10228 Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbi… Limesurvey Mitigation only Fix from $1,6002021-12-14 MEDIUM 6.1 CVE-2018-17003 In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/surve… Limesurvey No fix yet Fix from $1,6002018-09-21 MEDIUM 5.0 CVE-2011-3752 LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in… Limesurvey No fix yet Fix from $1,6002011-09-23 MEDIUM 6.8 CVE-2007-3632EPSS 62% Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a… Limesurvey No fix yet Fix from $1,6002007-07-10