Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Limesurvey HIGH 7.5
CVE-2025-41074

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploite…

Mitigation only
Fix from $1,950 2025-11-20
Limesurvey HIGH 7.5
CVE-2025-41075

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited …

Mitigation only
Fix from $1,950 2025-11-20
Limesurvey MEDIUM 6.5
CVE-2025-41076

In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displ…

Mitigation only
Fix from $1,600 2025-11-20
Limesurvey MEDIUM 6.1
CVE-2024-24506

Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code …

No fix yet
Fix from $1,600 2024-04-03
Limesurvey CRITICAL 9.8
CVE-2022-48008

An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $2,300 2023-01-27
Limesurvey MEDIUM 5.4
CVE-2022-48010

LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rende…

No fix yet
Fix from $1,600 2023-01-27
Limesurvey HIGH 8.8
CVE-2021-44967EPSS 14%

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious…

No fix yet
Fix from $1,950 2022-02-24
Limesurvey MEDIUM 6.1
CVE-2018-10228

Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbi…

Mitigation only
Fix from $1,600 2021-12-14
Limesurvey MEDIUM 6.1
CVE-2018-17003

In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/surve…

No fix yet
Fix from $1,600 2018-09-21
Limesurvey MEDIUM 5.0
CVE-2011-3752

LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in…

No fix yet
Fix from $1,600 2011-09-23
Limesurvey MEDIUM 6.8
CVE-2007-3632EPSS 62%

Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a…

No fix yet
Fix from $1,600 2007-07-10