CVE-2019-16173: Limesurvey

Medium severity, CVSS 5.4. EPSS: 3.7% chance of exploitation in the next 30 days.

LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,

Affected products

  • Limesurvey Limesurvey: before 3.17.4 (fixed in 3.17.4)

Published 2019-09-09. Last modified 2026-06-17.