Show filters
66 Total Results
Displaying 1-10 of 66
Sort by:
Attacker Value
Unknown
CVE-2024-28710
Disclosure Date: October 07, 2024 (last updated October 16, 2024)
Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.
0
Attacker Value
Unknown
CVE-2024-28709
Disclosure Date: October 07, 2024 (last updated October 16, 2024)
Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.
0
Attacker Value
Unknown
CVE-2024-42903
Disclosure Date: September 03, 2024 (last updated September 13, 2024)
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
0
Attacker Value
Unknown
CVE-2023-44796
Disclosure Date: November 18, 2023 (last updated November 25, 2023)
Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.
0
Attacker Value
Unknown
CVE-2022-48010
Disclosure Date: January 27, 2023 (last updated November 08, 2023)
LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description or Welcome-message text fields. NOTE: the vendor indicates that this is not a vulnerability because the manipulation requires Superadministrator privileges, and Superadministrators are already allowed to customize surveys with JavaScript as they wish.
0
Attacker Value
Unknown
CVE-2022-48008
Disclosure Date: January 27, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-43279
Disclosure Date: November 15, 2022 (last updated May 15, 2024)
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
0
Attacker Value
Unknown
CVE-2022-29710
Disclosure Date: May 25, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
0
Attacker Value
Unknown
CVE-2021-44967
Disclosure Date: February 24, 2022 (last updated February 20, 2025)
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.
0
Attacker Value
Unknown
CVE-2018-10228
Disclosure Date: December 14, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges URI.
0