CVE-2024-7887
- EPSS 0.9%
- Veröffentlicht 17.08.2024 09:15:12
- Zuletzt bearbeitet 30.01.2026 20:51:22
A vulnerability was found in LimeSurvey 6.3.0-231016 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php of the component File Upload. The manipulation of the argument size leads to denial of ser...
CVE-2024-6933
- EPSS 0.56%
- Veröffentlicht 21.07.2024 01:15:10
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey...
CVE-2024-39063
- EPSS 0.3%
- Veröffentlicht 09.07.2024 20:15:12
- Zuletzt bearbeitet 30.01.2026 20:52:36
Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests, but the same check isn't performed in the equivalent GET requests.
CVE-2024-24506
- EPSS 0.68%
- Veröffentlicht 03.04.2024 07:15:42
- Zuletzt bearbeitet 30.01.2026 21:02:09
Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.
CVE-2023-44796
- EPSS 0.68%
- Veröffentlicht 18.11.2023 00:15:07
- Zuletzt bearbeitet 21.11.2024 08:26:02
Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.
CVE-2022-48010
- EPSS 0.48%
- Veröffentlicht 27.01.2023 18:15:15
- Zuletzt bearbeitet 21.11.2024 07:32:41
LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scr...
CVE-2022-48008
- EPSS 1.27%
- Veröffentlicht 27.01.2023 18:15:15
- Zuletzt bearbeitet 28.03.2025 17:15:24
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-43279
- EPSS 0.86%
- Veröffentlicht 15.11.2022 21:15:38
- Zuletzt bearbeitet 21.11.2024 07:26:11
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
CVE-2022-29710
- EPSS 0.76%
- Veröffentlicht 25.05.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:59:35
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
- EPSS 13.5%
- Veröffentlicht 24.02.2022 15:15:24
- Zuletzt bearbeitet 20.02.2025 03:15:11
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally ...