Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

LimeSurvey — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in LimeSurvey, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities associated with the LimeSurvey product, categorized by weakness type and vulnerability tag. It collects a comprehensive set of security flaws discovered within this open-source web application survey tool, covering the historical period from the product's initial public release through the most recent disclosed security advisories. Readers can use this section to track the vendor's advisory history, understand the specific weakness classes affecting the software, and review the complete vulnerability timeline for this product. The aggregation helps security teams identify recurring patterns, such as common input validation errors or authentication bypasses, without needing to parse individual vendor bulletins separately.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-102626 LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute CWE-79 7.2 High 2026-10-02
CVE-2026-97685 LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations CWE-639 7.1 High 2026-09-29
CVE-2026-92730 LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name CWE-79 7.4 High 2026-09-23
CVE-2026-91775 LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings CWE-79 7.4 High 2026-09-23
CVE-2026-65931 LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu entry creation endpoint CWE-862 5.1 Medium 2026-08-27
CVE-2026-63360 LimeSurvey Community Edition 7.0.5 - Reflected XSS in user activation confirmation endpoint CWE-79 7.4 High 2026-08-26
CVE-2026-16809 LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering CWE-79 7.2 High 2026-08-26
CVE-2026-65930 LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields CWE-79 4.8 Medium 2026-08-26
CVE-2026-15973 LimeSurvey 7.0.5 - Stored XSS in Survey Menu Entries CWE-79 8.4 High 2026-08-26
CVE-2026-18403 LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB CWE-89 6.0 Medium 2026-08-14
CVE-2026-63361 LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup CWE-79 8.5 High 2026-08-14
CVE-2026-63107 LimeSurvey SSRF via REST API Survey Template Host Header CWE-918 7.7 High 2026-07-20
CVE-2026-50636 LimeSurvey RemoteControl invite_participants/remind_participants SQL Injection CWE-89 8.8 High 2026-06-09
CVE-2026-50635 LimeSurvey Password Reset Host Header Injection Discloses Reset Token CWE-640 8.8 High 2026-06-09
CVE-2020-36993 LimeSurvey <= 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting CWE-79 5.4 Medium 2026-01-28
CVE-2025-41076 Multiple vulnerabilities in Limesurvey CWE-209 7.5 - 2025-11-20
CVE-2025-41075 Multiple vulnerabilities in Limesurvey CWE-835 6.5 - 2025-11-20
CVE-2025-41074 Multiple vulnerabilities in Limesurvey CWE-835 6.5 - 2025-11-20
CVE-2025-41376 CRLF Injection in Limesurvey CWE-93 8.8 - 2025-08-01
CVE-2025-41375 SQL Injection in Limesurvey CWE-89 8.8 - 2025-08-01
CVE-2025-34120 LimeSurvey 2.0+ - 2.06+ Unauthenticated Arbitrary File Download via Serialized Backup Payload CWE-22 7.5AI High AI 2025-07-16
CVE-2024-7887 LimeSurvey File Upload index.php denial of service CWE-404 2.7 Low 2024-08-17
CVE-2024-6933 LimeSurvey Survey General Settings updatesurveylocalesettings_generalsettings actionUpdateSurveyLocaleSettingsGeneralSettings sql injection CWE-89 6.3 Medium 2024-07-21

All 23 known CVE vulnerabilities affecting LimeSurvey with full Chinese analysis, references, and POCs where available.