lacrioque
18 exploits
Active since Aug 2019
Limesurvey < 3.17.10 - Unauthenticated Arbitrary File Upload via Image MIME Type Bypass
CVSS 7.5
Limesurvey <3.17.14 - Code Injection
CVSS 8.8
LimeSurvey < 3.17.14 - Clickjacking
CVSS 4.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 5.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 7.5
LimeSurvey < 3.17.14 - Authenticated Stored Cross-Site Scripting via Admin Box Button Titles
CVSS 5.4
Limesurvey <3.17.14 - Info Disclosure
CVSS 5.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 5.3
Limesurvey <3.17.14 - Info Disclosure
CVSS 2.7
LimeSurvey < 3.17.14 - Reflected Cross-Site Scripting via Uploaded File Extensions
CVSS 6.1
Limesurvey <3.17.14 - Info Disclosure
CVSS 2.7
Limesurvey <3.17.14 - Command Injection
CVSS 9.8
Limesurvey <3.17.14 - Info Disclosure
CVSS 7.2
Limesurvey <3.17.14 - Privilege Escalation
CVSS 7.2
LimeSurvey < 3.17.14 - Unauthenticated Cookie Access via Missing HttpOnly Flag
CVSS 7.5
LimeSurvey 3.21.1 - Stored Cross-Site Scripting in Add Participants Function
CVSS 5.4
LimeSurvey <= 3.21.1 - Authenticated Stored Cross-Site Scripting via ParticipantAttributeNamesDropdown
CVSS 5.4
LimeSurvey 3.21.1 - Stored Cross-Site Scripting in Quota Component
CVSS 5.4