CVE-2019-16184: Limesurvey

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.

Affected products

  • Limesurvey Limesurvey: before 3.17.14 (fixed in 3.17.14)

Published 2019-09-09. Last modified 2026-06-17.