Known Vulnerabilities for products from LimeSurvey
Listed below are 20 of the newest known vulnerabilities associated with the vendor "LimeSurvey".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65931 json | Not Provided | 2026-08-27 | 2026-08-28 | |
| CVE-2026-65930 json | Not Provided | 2026-08-26 | 2026-08-27 | |
| CVE-2026-63361 json | Not Provided | 2026-08-14 | 2026-08-26 | |
| CVE-2026-63360 json | Not Provided | 2026-08-26 | 2026-08-27 | |
| CVE-2026-63107 json | Not Provided | 2026-07-20 | 2026-07-23 | |
| CVE-2026-50636 json | Not Provided | 2026-06-09 | 2026-06-23 | |
| CVE-2026-50635 json | Not Provided | 2026-06-09 | 2026-06-23 | |
| CVE-2026-18403 json | Not Provided | 2026-08-14 | 2026-08-14 | |
| CVE-2026-16809 json | Not Provided | 2026-08-26 | 2026-08-27 | |
| CVE-2026-15973 json | Not Provided | 2026-08-26 | 2026-08-27 | |
| CVE-2025-70797 json | Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the ... | Not Provided | 2026-04-09 | 2026-04-16 |
| CVE-2025-63238 json | A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of ... | Not Provided | 2026-04-09 | 2026-04-16 |
| CVE-2025-56422 json | A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the... | Not Provided | 2026-03-10 | 2026-07-05 |
| CVE-2025-56421 json | SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information fro... | Not Provided | 2026-03-10 | 2026-07-05 |
| CVE-2024-28710 json | Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a... | Not Provided | 2024-10-07 | 2026-07-05 |
| CVE-2024-28709 json | Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via ... | Not Provided | 2024-10-07 | 2026-07-05 |
| CVE-2024-6933 json | A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGen... | Not Provided | 2024-07-21 | 2026-04-29 |
| CVE-2022-48010 json | ** DISPUTED ** LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the componen... | 5.4 - MEDIUM | 2023-01-27 | 2023-11-07 |
| CVE-2022-48008 json | An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code... | 9.8 - CRITICAL | 2023-01-27 | 2023-02-04 |
| CVE-2022-43279 json | LimeSurvey v5.4.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/u... | 7.2 - HIGH | 2022-11-15 | 2022-11-17 |
Known software with vulnerabilities from LimeSurvey
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Limesurvey | Limesurvey | 1.01 |