Limesurvey

Limesurvey

92 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 02.10.2026 17:16:14
  • Zuletzt bearbeitet 02.10.2026 19:16:39

An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey i...

  • EPSS 0.24%
  • Veröffentlicht 29.09.2026 03:17:23
  • Zuletzt bearbeitet 30.09.2026 16:19:26

An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint ...

  • EPSS 0.39%
  • Veröffentlicht 23.09.2026 18:02:02
  • Zuletzt bearbeitet 23.09.2026 20:17:22

LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page.

  • EPSS 0.38%
  • Veröffentlicht 23.09.2026 17:13:46
  • Zuletzt bearbeitet 02.10.2026 18:17:07

LimeSurvey Community Edition 7.0.14 fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.

  • EPSS 0.29%
  • Veröffentlicht 27.08.2026 17:50:47
  • Zuletzt bearbeitet 28.08.2026 16:18:20

LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint. An authenticated user with only the global settings:read permission can directly invoke POST /index.php/a...

  • EPSS 0.27%
  • Veröffentlicht 26.08.2026 21:47:49
  • Zuletzt bearbeitet 28.08.2026 15:31:31

LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input att...

  • EPSS 0.24%
  • Veröffentlicht 26.08.2026 21:39:12
  • Zuletzt bearbeitet 28.08.2026 15:31:31

LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota m...

  • EPSS 0.24%
  • Veröffentlicht 26.08.2026 21:24:52
  • Zuletzt bearbeitet 28.08.2026 15:31:31

LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.

  • EPSS 0.26%
  • Veröffentlicht 26.08.2026 20:42:44
  • Zuletzt bearbeitet 28.08.2026 15:31:31

LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-...

  • EPSS 0.28%
  • Veröffentlicht 14.08.2026 18:33:31
  • Zuletzt bearbeitet 28.08.2026 15:31:31

LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list.