limesurvey/limesurvey Security Advisories for 6.2.5+230828 (5)
-
[HIGH] LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it.
PKSA-bgzx-wwbd-v2zr CVE-2026-50635 GHSA-5c37-5j7w-8mh8
Affected version: <=7.0.0-beta1
Reported by:
GitHub -
[HIGH] LimeSurvey has a SQL Injection issue
PKSA-jm8r-vn8x-qc36 CVE-2026-50636 GHSA-pr6f-87hf-hx24
Affected version: <=7.0.0-beta1
Reported by:
GitHub -
[HIGH] LimeSurvey is vulnerable to SQL injection
PKSA-g7yy-kkwv-8pkt CVE-2025-56421 GHSA-rccq-2fxq-7x3h
Affected version: <6.15.4
Reported by:
GitHub -
[MEDIUM] LimeSurvey Cross Site Scripting vulnerability
PKSA-6gp7-jzpy-gykg CVE-2024-28709 GHSA-c7xm-rwqj-pgcj
Affected version: <6.5.12
Reported by:
GitHub -
[MEDIUM] LimeSurvey Cross Site Scripting vulnerability
PKSA-23w5-jp48-9q58 CVE-2024-28710 GHSA-632q-77qj-c89q
Affected version: <6.5.0
Reported by:
GitHub