CVE-2018-1000053: Limesurvey
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, rendering the website unusable. This attack appear to be exploitable via Simple HTML markup can be used to send a GET request to the affected endpoint.
Affected products
- Limesurvey Limesurvey: version 3.0.0 only
Published 2018-02-09. Last modified 2026-06-17.