Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
limesurvey vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2019-16179
Limesurvey prior to 3.17.14 does not enforce SSL/TLS usage in the default configuration.
Limesurvey Limesurvey
5
CVSSv2
CVE-2019-16180
Limesurvey prior to 3.17.14 allows remote malicious users to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.
Limesurvey Limesurvey
4
CVSSv2
CVE-2019-16181
In Limesurvey prior to 3.17.14, admin users can mark other users' notifications as read.
Limesurvey Limesurvey
4.3
CVSSv2
CVE-2019-16182
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey prior to 3.17.14 that allows remote malicious users to inject arbitrary web script or HTML via extensions of uploaded files.
Limesurvey Limesurvey
4
CVSSv2
CVE-2019-16183
In Limesurvey prior to 3.17.14, admin users can run an integrity check without proper permissions.
Limesurvey Limesurvey
7.5
CVSSv2
CVE-2019-16184
A CSV injection vulnerability was found in Limesurvey prior to 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
Limesurvey Limesurvey
6.5
CVSSv2
CVE-2019-16185
In Limesurvey prior to 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
Limesurvey Limesurvey
6.5
CVSSv2
CVE-2019-16186
In Limesurvey prior to 3.17.14, admin users can access the plugin manager without proper permissions.
Limesurvey Limesurvey
5
CVSSv2
CVE-2019-16187
Limesurvey prior to 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows malicious users to access a cookie value via a client-side script.
Limesurvey Limesurvey
9.3
CVSSv2
CVE-2008-2570
Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) prior to 1.71 have unknown impact and attack vectors.
Limesurvey Limesurvey
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
injection
CVE-2024-30983
CVE-2023-4235
CVE-2024-21338
privilege
encryption
CVE-2023-4232
CVE-2024-31497
CVE-2024-32341
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »