CVE-2019-16172: Limesurvey
Medium severity, CVSS 5.4. EPSS: 4.6% chance of exploitation in the next 30 days.
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
Affected products
- Limesurvey Limesurvey: before 3.17.4 (fixed in 3.17.4)
Published 2019-09-09. Last modified 2026-06-17.