LimeSurvey

LimeSurvey (formerly PHPSurveyor) is an open source online survey application written in PHP based on a MySQL PostgreSQL or MSSQL database. It enables users without coding knowledge to develop publish and collect responses to surveys. Surveys can include branching custom preferred layout and design (using a web template system) and can provide basic statistical analysis of survey results.

Severity Summary:

Critical: 7 High: 13 Medium: 36 Low: 3
Reference
Title
Severity
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Vulnerability
Medium
LimeSurvey Improper Certificate Validation Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Vulnerability
Medium
LimeSurvey Improper Restriction of Rendered UI Layers or Frames Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
LimeSurvey Vulnerability
Low
LimeSurvey Incorrect Default Permissions Vulnerability
Low
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Low