Limesurvey is a widely deployed open-source survey and data-collection platform that, despite a narrow product portfolio, occupies a prominent position in the vulnerability landscape and presents a substantial attack surface through its web-facing deployment model. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a corresponding tendency toward public exploit code availability, reflecting the application's exposure to internet-connected threat actors. The recurring weakness classes—cross-site scripting, SQL injection, insecure file uploads, and cross-site request forgery—are characteristic of web-application input handling and session-management boundaries, and they recur persistently across the vendor's release cycle. Defenders should treat Limesurvey instances as requiring prompt patching, particularly where survey forms are internet-accessible or handle sensitive data collection, and should inventory deployed instances across their organizations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Limesurvey over time
Signals from CVEs in this vendor scope (85 CVEs).
85 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11455CRITICAL LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php. | Apr 1, 2020 | 9.8 | 93 | NO | YES |
CVE-2020-11456MEDIUM LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (aka survey groups). | Apr 1, 2020 | 5.4 | 61 | NO | YES |
CVE-2007-3632MEDIUM Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter t | Jul 10, 2007 | 6.8 | 60 | NO | YES |
CVE-2018-17057CRITICAL An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. | Sep 14, 2018 | 9.8 | 52 | NO | YES |
CVE-2019-9960CRITICAL The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path. | Mar 24, 2019 | 9.8 | 41 | NO | YES |
CVE-2026-63107HIGH LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the serv | Jul 20, 2026 | 7.7 | 34 | NO | NO |
CVE-2026-50635HIGH LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is | Jun 9, 2026 | 8.8 | 33 | NO | NO |
CVE-2025-56422CRITICAL A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server. | Mar 10, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-50636HIGH The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), which concatenates the values di | Jun 9, 2026 | 8.8 | 32 | NO | NO |
CVE-2012-4927HIGH SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames par | Sep 15, 2012 | 7.5 | 32 | NO | YES |
Signals from CVEs in this vendor scope (85 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Limesurvey.
Media articles that mention a CVE ID that affects a product developed by Limesurvey — matched by CVE ID, not by vendor name.