CVE-2019-9960: Limesurvey
Critical severity, CVSS 9.8. EPSS: 13.4% chance of exploitation in the next 30 days.
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.
Affected products
- Limesurvey Limesurvey: up to and including 3.16.1\+190225
Published 2019-03-24. Last modified 2026-06-17.