CVE-2018-7556
- EPSS 1.98%
- Veröffentlicht 28.02.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:21
LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file.
CVE-2018-1000053
- EPSS 0.59%
- Veröffentlicht 09.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:39:32
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, rendering the website unusable. This attack appear t...
CVE-2015-4628
- EPSS 1.56%
- Veröffentlicht 18.06.2015 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter.
CVE-2011-5256
- EPSS 0.9%
- Veröffentlicht 12.02.2013 20:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.
CVE-2012-4995
- EPSS 1.16%
- Veröffentlicht 19.09.2012 19:55:07
- Zuletzt bearbeitet 16.06.2026 23:46:02
Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: ...
CVE-2012-4994
- EPSS 1.04%
- Veröffentlicht 19.09.2012 19:55:07
- Zuletzt bearbeitet 16.06.2026 23:46:02
SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third p...
CVE-2012-4927
- EPSS 2.24%
- Veröffentlicht 15.09.2012 17:55:08
- Zuletzt bearbeitet 16.06.2026 23:45:54
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.
CVE-2009-1604
- EPSS 1.83%
- Veröffentlicht 11.05.2009 20:00:00
- Zuletzt bearbeitet 16.06.2026 23:07:37
Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/.
CVE-2008-2571
- EPSS 1.11%
- Veröffentlicht 06.06.2008 18:32:00
- Zuletzt bearbeitet 16.06.2026 22:54:01
Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action.
CVE-2008-2570
- EPSS 1.31%
- Veröffentlicht 06.06.2008 18:32:00
- Zuletzt bearbeitet 16.06.2026 22:54:00
Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.