Looking for the vulnerability index of Invicti's legacy products?

LimeSurvey

LimeSurvey (formerly PHPSurveyor) is an open source online survey application written in PHP based on a MySQL PostgreSQL or MSSQL database. It enables users without coding knowledge to develop publish and collect responses to surveys. Surveys can include branching custom preferred layout and design (using a web template system) and can provide basic statistical analysis of survey results.

Severity Summary:

Critical: 9 High: 18 Medium: 41 Low: 3
Reference
Title
Severity
LimeSurvey Improper Control of Generation of Code (Code Injection) Vulnerability
Medium
LimeSurvey Improper Neutralization of CRLF Sequences (CRLF Injection) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Generation of Error Message Containing Sensitive Information Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
Medium
LimeSurvey Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Vulnerability
Medium
LimeSurvey Improper Certificate Validation Vulnerability
Medium
LimeSurvey Vulnerability
Medium
LimeSurvey Improper Restriction of Rendered UI Layers or Frames Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium