Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
limesurvey limesurvey vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2019-16182
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey prior to 3.17.14 that allows remote malicious users to inject arbitrary web script or HTML via extensions of uploaded files.
Limesurvey Limesurvey
668
VMScore
CVE-2019-16184
A CSV injection vulnerability was found in Limesurvey prior to 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
Limesurvey Limesurvey
578
VMScore
CVE-2019-16186
In Limesurvey prior to 3.17.14, admin users can access the plugin manager without proper permissions.
Limesurvey Limesurvey
445
VMScore
CVE-2019-16187
Limesurvey prior to 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows malicious users to access a cookie value via a client-side script.
Limesurvey Limesurvey
355
VMScore
CVE-2019-16172
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
Limesurvey Limesurvey
1 EDB exploit
355
VMScore
CVE-2019-16173
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
Limesurvey Limesurvey
1 EDB exploit
445
VMScore
CVE-2019-15640
Limesurvey prior to 3.17.10 does not validate both the MIME type and file extension of an image.
Limesurvey Limesurvey
790
VMScore
CVE-2019-9960
The downloadZip function in application/controllers/admin/export.php in LimeSurvey up to and including 3.16.1+190225 allows a relative path.
Limesurvey Limesurvey
1 Metasploit module
383
VMScore
CVE-2017-18358
LimeSurvey prior to 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.
Limesurvey Limesurvey
383
VMScore
CVE-2018-20322
LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.
Limesurvey Limesurvey
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »