Vulnerabilities > Limesurvey > Limesurvey > 3.17.4

DATE CVE VULNERABILITY TITLE RISK
2019-09-09 CVE-2019-16175 Improper Restriction of Rendered UI Layers or Frames vulnerability in Limesurvey
A clickjacking vulnerability was found in Limesurvey before 3.17.14.
4.3
2019-09-09 CVE-2019-16174 XXE vulnerability in Limesurvey
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
6.8
2019-08-26 CVE-2019-15640 Improper Input Validation vulnerability in Limesurvey
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
network
low complexity
limesurvey CWE-20
5.0