CVE-2018-17003: Limesurvey
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
Affected products
- Limesurvey Limesurvey: version 3.14.7 only
Published 2018-09-21. Last modified 2026-06-17.