Vulnerabilities > Limesurvey > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-06-28 | CVE-2020-23710 | Cross-site Scripting vulnerability in Limesurvey 4.2.5 Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature. | 3.5 |
2020-12-31 | CVE-2020-25797 | Cross-site Scripting vulnerability in Limesurvey 3.21.1 LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). | 3.5 |
2020-12-31 | CVE-2020-25799 | Cross-site Scripting vulnerability in Limesurvey 3.21.1 LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. | 3.5 |
2020-11-17 | CVE-2020-25798 | Cross-site Scripting vulnerability in Limesurvey A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant database page. | 3.5 |
2020-04-01 | CVE-2020-11456 | Cross-site Scripting vulnerability in Limesurvey LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (aka survey groups). | 3.5 |
2019-09-09 | CVE-2019-16178 | Cross-site Scripting vulnerability in Limesurvey A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page. | 3.5 |
2018-06-26 | CVE-2018-1000513 | Cross-site Scripting vulnerability in Limesurvey 3.0.0 LimeSurvey version 3.0.0-beta.3+17110 contains a Cross Site Scripting (XSS) vulnerability in Boxes that can result in JS code execution against LimeSurvey admins. | 3.5 |
2013-02-12 | CVE-2011-5256 | Cross-Site Scripting vulnerability in Limesurvey Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters. | 2.6 |