Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
limesurvey limesurvey vulnerabilities and exploits
(subscribe to this query)
312
VMScore
CVE-2019-16178
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey prior to 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page.
Limesurvey Limesurvey
445
VMScore
CVE-2019-16179
Limesurvey prior to 3.17.14 does not enforce SSL/TLS usage in the default configuration.
Limesurvey Limesurvey
445
VMScore
CVE-2019-16180
Limesurvey prior to 3.17.14 allows remote malicious users to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.
Limesurvey Limesurvey
356
VMScore
CVE-2019-16181
In Limesurvey prior to 3.17.14, admin users can mark other users' notifications as read.
Limesurvey Limesurvey
383
VMScore
CVE-2019-16182
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey prior to 3.17.14 that allows remote malicious users to inject arbitrary web script or HTML via extensions of uploaded files.
Limesurvey Limesurvey
383
VMScore
CVE-2018-20322
LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.
Limesurvey Limesurvey
828
VMScore
CVE-2008-2570
Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) prior to 1.71 have unknown impact and attack vectors.
Limesurvey Limesurvey
383
VMScore
CVE-2022-29710
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows malicious users to execute arbitrary web scripts or HTML via a crafted plugin.
Limesurvey Limesurvey
383
VMScore
CVE-2021-42112
The "File upload question" functionality in LimeSurvey 3.x-LTS up to and including 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
Limesurvey Limesurvey
383
VMScore
CVE-2019-17660
A cross-site scripting (XSS) vulnerability in admin/translate/translateheader_view.php in LimeSurvey 3.19.1 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the tolang parameter, as demonstrated by the index.php/admin/translate/sa/ind...
Limesurvey Limesurvey
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-0044
remote code execution
CVE-2024-37080
CVE-2024-5182
CVE-2024-4390
CVE-2024-6100
brute force
CVE-2021-47581
file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »