Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
limesurvey vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2019-16186
In Limesurvey prior to 3.17.14, admin users can access the plugin manager without proper permissions.
Limesurvey Limesurvey
4
CVSSv2
CVE-2019-16181
In Limesurvey prior to 3.17.14, admin users can mark other users' notifications as read.
Limesurvey Limesurvey
4
CVSSv2
CVE-2019-16183
In Limesurvey prior to 3.17.14, admin users can run an integrity check without proper permissions.
Limesurvey Limesurvey
5
CVSSv2
CVE-2019-16187
Limesurvey prior to 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows malicious users to access a cookie value via a client-side script.
Limesurvey Limesurvey
3.5
CVSSv2
CVE-2019-16172
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
Limesurvey Limesurvey
1 EDB exploit
3.5
CVSSv2
CVE-2019-16173
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
Limesurvey Limesurvey
1 EDB exploit
5
CVSSv2
CVE-2019-15640
Limesurvey prior to 3.17.10 does not validate both the MIME type and file extension of an image.
Limesurvey Limesurvey
7.5
CVSSv2
CVE-2019-9960
The downloadZip function in application/controllers/admin/export.php in LimeSurvey up to and including 3.16.1+190225 allows a relative path.
Limesurvey Limesurvey
1 Metasploit module
4.3
CVSSv2
CVE-2017-18358
LimeSurvey prior to 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.
Limesurvey Limesurvey
4.3
CVSSv2
CVE-2018-20322
LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.
Limesurvey Limesurvey
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »