Limesurvey

Limesurvey

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 03.09.2024 18:15:08
  • Zuletzt bearbeitet 03.07.2025 12:59:01

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function

Exploit
  • EPSS 0.16%
  • Veröffentlicht 03.09.2024 18:15:08
  • Zuletzt bearbeitet 03.07.2025 13:04:06

A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 17.08.2024 09:15:12
  • Zuletzt bearbeitet 30.01.2026 20:51:22

A vulnerability was found in LimeSurvey 6.3.0-231016 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php of the component File Upload. The manipulation of the argument size leads to denial of ser...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 21.07.2024 01:15:10
  • Zuletzt bearbeitet 30.01.2026 21:41:54

A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 09.07.2024 20:15:12
  • Zuletzt bearbeitet 30.01.2026 20:52:36

Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests, but the same check isn't performed in the equivalent GET requests.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 03.04.2024 07:15:42
  • Zuletzt bearbeitet 30.01.2026 21:02:09

Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 18.11.2023 00:15:07
  • Zuletzt bearbeitet 21.11.2024 08:26:02

Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 27.01.2023 18:15:15
  • Zuletzt bearbeitet 21.11.2024 07:32:41

LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scr...

Exploit
  • EPSS 5.76%
  • Veröffentlicht 27.01.2023 18:15:15
  • Zuletzt bearbeitet 28.03.2025 17:15:24

An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 15.11.2022 21:15:38
  • Zuletzt bearbeitet 21.11.2024 07:26:11

LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.