CVE-2024-24506: Limesurvey

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.

Affected products

Published 2024-04-03. Last modified 2026-06-17.