Limesurvey

Limesurvey

92 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 20.11.2025 12:49:29
  • Zuletzt bearbeitet 21.11.2025 19:59:05

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The syst...

  • EPSS 0.31%
  • Veröffentlicht 20.11.2025 12:47:05
  • Zuletzt bearbeitet 21.11.2025 20:00:55

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The sy...

  • EPSS 0.51%
  • Veröffentlicht 01.08.2025 12:29:59
  • Zuletzt bearbeitet 30.01.2026 21:44:53

CRLF Injection vulnerability in Limesurvey v2.65.1+170522.  This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid/<SID>/token/fwyfw%0d%0aCookie:%...

  • EPSS 0.63%
  • Veröffentlicht 01.08.2025 12:29:48
  • Zuletzt bearbeitet 30.01.2026 21:45:13

SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via 'token' parameter in '/index.php' endpoint.

  • EPSS 1.21%
  • Veröffentlicht 16.07.2025 21:15:26
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 151014. The application fails to validate serialized input to the admin backup endpoint (`index.php/admin/update/sa/backup`), allow...

  • EPSS 0.54%
  • Veröffentlicht 07.10.2024 16:15:05
  • Zuletzt bearbeitet 05.07.2026 01:19:35

Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.

  • EPSS 0.54%
  • Veröffentlicht 07.10.2024 16:15:05
  • Zuletzt bearbeitet 05.07.2026 01:19:34

Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.

  • EPSS 0.5%
  • Veröffentlicht 03.09.2024 18:15:08
  • Zuletzt bearbeitet 13.03.2025 21:15:41

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.

Exploit
  • EPSS 1.02%
  • Veröffentlicht 03.09.2024 18:15:08
  • Zuletzt bearbeitet 03.07.2025 12:59:01

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function

Exploit
  • EPSS 0.43%
  • Veröffentlicht 03.09.2024 18:15:08
  • Zuletzt bearbeitet 03.07.2025 13:04:06

A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.