CVE-2011-5256: Limesurvey

Low severity, CVSS 2.6. EPSS: 0.9% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.

Affected products

  • Limesurvey Limesurvey: up to and including 1.91\+; version 1.01 only; version 1.50 only; version 1.52 only; version 1.53+ only; version 1.70+ only; …

Published 2013-02-12. Last modified 2026-06-16.