LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability - CVE-2021-44967
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function which could let a remote malicious user upload an arbitrary PHP code file.