CVE-2018-17057: Limesurvey
Critical severity, CVSS 9.8. EPSS: 26.2% chance of exploitation in the next 30 days.
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
Affected products
- Limesurvey Limesurvey: before 3.16.0 (fixed in 3.16.0)
- Tecnick Tcpdf: before 6.2.22 (fixed in 6.2.22)
Published 2018-09-14. Last modified 2026-06-17.