« Volver al listado

Limesurvey

Limesurvey Community Edition: vulnerabilidades y CVE

Limesurvey Community Edition tiene 7 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses7
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-102626Alta (7.2)0.27%—2 oct 2026
An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the…
CVE-2026-97685Alta (7.1)0.24%—29 sept 2026
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The…
CVE-2026-65930Media (4.8)0.41%—26 ago 2026
LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.
CVE-2026-63360Alta (7.4)0.46%—26 ago 2026
LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and…
CVE-2026-16809Alta (7.2)0.24%—26 ago 2026
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store…
CVE-2026-15973Alta (8.4)0.26%—26 ago 2026
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey…
CVE-2026-63361Alta (8.5)0.53%—14 ago 2026
LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript5
  2. T1189 Drive-by Compromise5
  3. T1210 Exploitation of Remote Services1
  4. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Limesurvey