CVE-2025-41376: Limesurvey

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

CRLF Injection vulnerability in Limesurvey v2.65.1+170522.  This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid/<SID>/token/fwyfw%0d%0aCookie:%20POC'.

Affected products

  • Limesurvey Limesurvey: from 2.65.1, before 3.0.0 (fixed in 3.0.0)

Published 2025-08-01. Last modified 2026-06-17.