CVE-2019-16180: Limesurvey
Medium severity, CVSS 5.3. EPSS: 1.7% chance of exploitation in the next 30 days.
Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.
Affected products
- Limesurvey Limesurvey: before 3.17.14 (fixed in 3.17.14)
Published 2019-09-09. Last modified 2026-06-17.