Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
limesurvey vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2019-16178
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey prior to 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page.
Limesurvey Limesurvey
5.3
CVSSv3
CVE-2019-16179
Limesurvey prior to 3.17.14 does not enforce SSL/TLS usage in the default configuration.
Limesurvey Limesurvey
5.3
CVSSv3
CVE-2019-16180
Limesurvey prior to 3.17.14 allows remote malicious users to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.
Limesurvey Limesurvey
6.1
CVSSv3
CVE-2019-16182
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey prior to 3.17.14 that allows remote malicious users to inject arbitrary web script or HTML via extensions of uploaded files.
Limesurvey Limesurvey
9.8
CVSSv3
CVE-2019-16184
A CSV injection vulnerability was found in Limesurvey prior to 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
Limesurvey Limesurvey
7.2
CVSSv3
CVE-2019-16185
In Limesurvey prior to 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
Limesurvey Limesurvey
7.2
CVSSv3
CVE-2019-16186
In Limesurvey prior to 3.17.14, admin users can access the plugin manager without proper permissions.
Limesurvey Limesurvey
6.1
CVSSv3
CVE-2021-42112
The "File upload question" functionality in LimeSurvey 3.x-LTS up to and including 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
Limesurvey Limesurvey
8.8
CVSSv3
CVE-2018-1000659
LimeSurvey version 3.14.4 and previous versions contains a directory traversal in file upload that allows upload of webshell vulnerability in file upload functionality that can result in remote code execution as authenticated user. This attack appear to be exploitable via An auth...
Limesurvey Limesurvey
NA
CVE-2015-4628
SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey prior to 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter.
Limesurvey Limesurvey
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
CVE-2006-4304
wireless
CVE-2023-23022
local file inclusion
CVE-2024-27058
CVE-2024-33820
open redirect
CVE-2024-27079
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »