CVE-2025-41376: Limesurvey
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid/<SID>/token/fwyfw%0d%0aCookie:%20POC'.
Affected products
- Limesurvey Limesurvey: from 2.65.1, before 3.0.0 (fixed in 3.0.0)
Published 2025-08-01. Last modified 2026-06-17.