CVE-2022-48008
- EPSS 5.76%
- Veröffentlicht 27.01.2023 18:15:15
- Zuletzt bearbeitet 28.03.2025 17:15:24
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-43279
- EPSS 0.28%
- Veröffentlicht 15.11.2022 21:15:38
- Zuletzt bearbeitet 21.11.2024 07:26:11
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
CVE-2022-29710
- EPSS 0.47%
- Veröffentlicht 25.05.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:59:35
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
- EPSS 75.88%
- Veröffentlicht 24.02.2022 15:15:24
- Zuletzt bearbeitet 20.02.2025 03:15:11
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally ...
CVE-2018-10228
- EPSS 0.23%
- Veröffentlicht 14.12.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 03:41:03
Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavech...
CVE-2021-42112
- EPSS 0.58%
- Veröffentlicht 08.10.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:17
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
CVE-2020-22607
- EPSS 0.22%
- Veröffentlicht 28.06.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:13:18
Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php.
CVE-2020-23710
- EPSS 0.28%
- Veröffentlicht 28.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:14:01
Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.
CVE-2019-25019
- EPSS 0.44%
- Veröffentlicht 14.02.2021 04:15:12
- Zuletzt bearbeitet 21.11.2024 04:39:45
LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.
CVE-2020-25799
- EPSS 0.26%
- Veröffentlicht 31.12.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:48
LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.