Vulnerability index

Browse CVEs

67 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Limesurvey MEDIUM 5.4
CVE-2020-25798

A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to in…

Fix: after 3.21.1
Fix from $1,600 2020-11-17
Limesurvey MEDIUM 6.1
CVE-2020-16192

LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.

Patch available
Fix from $1,600 2020-08-05
Limesurvey CRITICAL 9.8
CVE-2020-11455EPSS 97%

LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.

Fix: after 4.1.11
Fix from $2,300 2020-04-01
Limesurvey MEDIUM 5.4
CVE-2020-11456EPSS 71%

LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (…

Fix: after 4.1.11
Fix from $1,600 2020-04-01
Limesurvey MEDIUM 6.1
CVE-2019-14512

LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in application/views/admin/labels/…

Patch available
Fix from $1,600 2020-03-16
Limesurvey MEDIUM 6.1
CVE-2019-17660

A cross-site scripting (XSS) vulnerability in admin/translate/translateheader_view.php in LimeSurvey 3.19.1 and earlier allows remote attackers to in…

Fix: after 3.19.1
Fix from $1,600 2019-10-16
Limesurvey HIGH 7.5
CVE-2019-16187

Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side scrip…

Fix: 3.17.14+
Fix from $1,950 2019-09-09
Limesurvey HIGH 7.2
CVE-2019-16186

In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.

Fix: 3.17.14+
Fix from $1,950 2019-09-09
Limesurvey CRITICAL 9.8
CVE-2019-16184

A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses th…

Fix: 3.17.14+
Fix from $2,300 2019-09-09
Limesurvey HIGH 8.8
CVE-2019-16174

An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute …

Fix: 3.17.14+
Fix from $1,950 2019-09-09
Limesurvey HIGH 7.5
CVE-2019-16177

In Limesurvey before 3.17.14, the entire database is exposed through browser caching.

Fix: 3.17.14+
Fix from $1,950 2019-09-09
Limesurvey HIGH 7.2
CVE-2019-16185

In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.

Fix: 3.17.14+
Fix from $1,950 2019-09-09
Limesurvey MEDIUM 6.1
CVE-2019-16182

A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web scri…

Fix: 3.17.14+
Fix from $1,600 2019-09-09
Limesurvey MEDIUM 5.4
CVE-2019-16178

A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to …

Fix: 3.17.14+
Fix from $1,600 2019-09-09
Limesurvey MEDIUM 5.3
CVE-2019-16176

A path disclosure vulnerability was found in Limesurvey before 3.17.14 that allows a remote attacker to discover the path to the application in the f…

Fix: 3.17.14+
Fix from $1,600 2019-09-09
Limesurvey MEDIUM 5.3
CVE-2019-16179

Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration.

Fix: 3.17.14+
Fix from $1,600 2019-09-09
Limesurvey MEDIUM 5.3
CVE-2019-16180

Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.

Fix: 3.17.14+
Fix from $1,600 2019-09-09
Limesurvey MEDIUM 5.4
CVE-2019-16172

LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a s…

Fix: 3.17.4+
Fix from $1,600 2019-09-09
Limesurvey MEDIUM 5.4
CVE-2019-16173

LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in a…

Fix: 3.17.4+
Fix from $1,600 2019-09-09
Limesurvey HIGH 7.5
CVE-2019-15640

Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.

Fix: 3.17.10+
Fix from $1,950 2019-08-26
Limesurvey CRITICAL 9.8
CVE-2019-9960EPSS 13%

The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.

Fix: after 3.16.1
Fix from $2,300 2019-03-24
Limesurvey MEDIUM 6.1
CVE-2017-18358

LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the …

Fix: 2.72.4+
Fix from $1,600 2019-01-15
Limesurvey MEDIUM 6.1
CVE-2018-20322

LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution a…

Fix: after 3.15.5
Fix from $1,600 2018-12-21
Limesurvey MEDIUM 6.1
CVE-2018-17003

In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/surve…

No fix yet
Fix from $1,600 2018-09-21
Limesurvey HIGH 8.8
CVE-2018-1000658

LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution…

Fix: 3.14.4+
Fix from $1,950 2018-09-06
Limesurvey HIGH 8.8
CVE-2018-1000659

LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulnerability in file upload funct…

Fix: after 3.14.4
Fix from $1,950 2018-09-06
Limesurvey HIGH 8.8
CVE-2018-1000053

LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causi…

Patch available
Fix from $1,950 2018-02-09
Limesurvey MEDIUM 6.5
CVE-2015-5078

SQL injection vulnerability in the insert function in application/controllers/admin/dataentry.php in LimeSurvey 2.06+ allows remote authenticated use…

Patch available
Fix from $1,600 2015-06-28
Limesurvey MEDIUM 6.5
CVE-2015-4628

SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated a…

Fix: after 2.06
Fix from $1,600 2015-06-18
Limesurvey HIGH 7.5
CVE-2014-5017

SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers …

Patch available
Fix from $1,950 2014-07-21