CVE-2025-41074: Limesurvey
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.
Affected products
- Limesurvey Limesurvey: version 6.13.0 only
Published 2025-11-20. Last modified 2026-06-17.