Limesurvey
by Limesurvey
Source repositories
CVEs (88)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16177 | Hig | 0.42 | 7.5 | 0.01 | Sep 9, 2019 | In Limesurvey before 3.17.14, the entire database is exposed through browser caching. | ||
| CVE-2024-24506 | Med | 0.40 | 6.1 | 0.01 | Apr 3, 2024 | Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function. | ||
| CVE-2018-10228 | Med | 0.40 | 6.1 | 0.01 | Dec 14, 2021 | Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges URI. | ||
| CVE-2019-17660 | Med | 0.40 | 6.1 | 0.01 | Oct 16, 2019 | A cross-site scripting (XSS) vulnerability in admin/translate/translateheader_view.php in LimeSurvey 3.19.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the tolang parameter, as demonstrated by the index.php/admin/translate/sa/index/surveyid/3368… | ||
| CVE-2019-16186 | Hig | 0.40 | 7.2 | 0.01 | Sep 9, 2019 | In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions. | ||
| CVE-2019-16185 | Hig | 0.40 | 7.2 | 0.01 | Sep 9, 2019 | In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions. | ||
| CVE-2018-17003 | Med | 0.40 | 6.1 | 0.01 | Sep 21, 2018 | In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert. | ||
| CVE-2022-48010 | Med | 0.35 | 5.4 | 0.00 | Jan 27, 2023 | LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted… | ||
| CVE-2020-23710 | Med | 0.35 | 5.4 | 0.01 | Jun 28, 2021 | Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature. | ||
| CVE-2025-41376 | Med | 0.34 | 5.3 | 0.01 | Aug 1, 2025 | CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid//token/fwyfw%0d%0aCookie:%20POC'. | ||
| CVE-2024-6933 | Med | 0.34 | 6.3 | 0.01 | Jul 21, 2024 | A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler.… | ||
| CVE-2025-70797 | Med | 0.33 | 6.1 | 0.00 | Apr 9, 2026 | Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] parameters. | ||
| CVE-2025-63238 | Med | 0.33 | 6.1 | 0.00 | Apr 9, 2026 | A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInstance() function in application/models/QuestionCreate.php. This allows an attacker to craft a malicious URL and compromise the… | ||
| CVE-2024-28710 | Med | 0.33 | 6.1 | 0.01 | Oct 7, 2024 | Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component. | ||
| CVE-2024-28709 | Med | 0.33 | 6.1 | 0.01 | Oct 7, 2024 | Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields. | ||
| CVE-2021-42112 | Med | 0.33 | 6.1 | 0.02 | Oct 8, 2021 | The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js. | ||
| CVE-2019-16182 | Med | 0.33 | 6.1 | 0.01 | Sep 9, 2019 | A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files. | ||
| CVE-2026-18403 | Med | 0.32 | — | — | Aug 14, 2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list. | ||
| CVE-2018-16397 | Med | 0.32 | 4.9 | 0.01 | Sep 3, 2018 | In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file, | ||
| CVE-2019-16173 | Med | 0.31 | 5.4 | 0.04 | Sep 9, 2019 | LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php, |
- risk 0.42cvss 7.5epss 0.01
In Limesurvey before 3.17.14, the entire database is exposed through browser caching.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges URI.
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in admin/translate/translateheader_view.php in LimeSurvey 3.19.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the tolang parameter, as demonstrated by the index.php/admin/translate/sa/index/surveyid/3368…
- risk 0.40cvss 7.2epss 0.01
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
- risk 0.40cvss 7.2epss 0.01
In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
- risk 0.40cvss 6.1epss 0.01
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
- risk 0.35cvss 5.4epss 0.00
LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted…
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.
- risk 0.34cvss 5.3epss 0.01
CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid//token/fwyfw%0d%0aCookie:%20POC'.
- risk 0.34cvss 6.3epss 0.01
A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler.…
- risk 0.33cvss 6.1epss 0.00
Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] parameters.
- risk 0.33cvss 6.1epss 0.00
A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInstance() function in application/models/QuestionCreate.php. This allows an attacker to craft a malicious URL and compromise the…
- risk 0.33cvss 6.1epss 0.01
Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.
- risk 0.33cvss 6.1epss 0.01
Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.
- risk 0.33cvss 6.1epss 0.02
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
- risk 0.33cvss 6.1epss 0.01
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files.
- risk 0.32cvss —epss —
LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list.
- risk 0.32cvss 4.9epss 0.01
In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,
- risk 0.31cvss 5.4epss 0.04
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
Page 2 of 5