Vulnerability index

Browse CVEs

67 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-63238 A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInst… Limesurvey 6.15.12+ Fix from $1,6002026-04-09 MEDIUM 6.1 CVE-2025-70797 Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] … Limesurvey Patch available Fix from $1,6002026-04-09 CRITICAL 9.8 CVE-2025-56422 A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server. Limesurvey after 6.14.3 Fix from $2,3002026-03-10 HIGH 7.5 CVE-2025-56421 SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database. Limesurvey after 6.15.3 Fix from $1,9502026-03-10 MEDIUM 5.4 CVE-2020-36993 LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can in… Limesurvey after 4.3.10 Fix from $1,6002026-01-28 HIGH 7.5 CVE-2025-41074 Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploite… Limesurvey Mitigation only Fix from $1,9502025-11-20 HIGH 7.5 CVE-2025-41075 Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited … Limesurvey Mitigation only Fix from $1,9502025-11-20 MEDIUM 6.5 CVE-2025-41076 In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displ… Limesurvey Mitigation only Fix from $1,6002025-11-20 CRITICAL 9.8 CVE-2025-41375 SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via '… Limesurvey 3.0.0+ Fix from $2,3002025-08-01 MEDIUM 5.3 CVE-2025-41376 CRLF Injection vulnerability in Limesurvey v2.65.1+170522.  This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and per… Limesurvey 3.0.0+ Fix from $1,6002025-08-01 MEDIUM 6.1 CVE-2024-28709 Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the … Limesurvey 6.5.12+ Fix from $1,6002024-10-07 MEDIUM 6.1 CVE-2024-28710 Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validatio… Limesurvey 6.5.0+ Fix from $1,6002024-10-07 HIGH 8.8 CVE-2024-42902 An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload i… Limesurvey after 6.6.2 Fix from $1,9502024-09-03 MEDIUM 6.5 CVE-2024-42903 A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted… Limesurvey after 6.6.1 Fix from $1,6002024-09-03 CRITICAL 9.8 CVE-2024-6933 A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file… Limesurvey 6.6.2+ Fix from $2,3002024-07-21 HIGH 8.8 CVE-2024-39063 Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests… Limesurvey after 6.5.12 Fix from $1,9502024-07-09 MEDIUM 6.1 CVE-2024-24506 Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code … Limesurvey No fix yet Fix from $1,6002024-04-03 MEDIUM 5.4 CVE-2023-44796 Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted scri… Limesurvey 6.2.9+ Fix from $1,6002023-11-18 CRITICAL 9.8 CVE-2022-48008 An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file. Limesurvey No fix yet Fix from $2,3002023-01-27 MEDIUM 5.4 CVE-2022-48010 LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rende… Limesurvey No fix yet Fix from $1,6002023-01-27 HIGH 7.2 CVE-2022-43279 LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php. Limesurvey Patch available Fix from $1,9502022-11-15 MEDIUM 6.1 CVE-2022-29710 A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or H… Limesurvey after 5.3.9 Fix from $1,6002022-05-25 HIGH 8.8 CVE-2021-44967EPSS 14% A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious… Limesurvey No fix yet Fix from $1,9502022-02-24 MEDIUM 6.1 CVE-2018-10228 Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbi… Limesurvey Mitigation only Fix from $1,6002021-12-14 MEDIUM 6.1 CVE-2021-42112 The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploade… Limesurvey after 3.27.18 Fix from $1,6002021-10-08 MEDIUM 6.1 CVE-2020-22607 Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/Permis… Limesurvey Patch available Fix from $1,6002021-06-28 MEDIUM 5.4 CVE-2020-23710 Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature. Limesurvey Patch available Fix from $1,6002021-06-28 CRITICAL 9.8 CVE-2019-25019 LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model. Limesurvey 3.19.0+ Fix from $2,3002021-02-14 MEDIUM 5.4 CVE-2020-25797 LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey partic… Limesurvey Patch available Fix from $1,6002020-12-31 MEDIUM 5.4 CVE-2020-25799 LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an… Limesurvey Patch available Fix from $1,6002020-12-31