← Vulnerability feed

Vulnerability record · CVE-2025-41375 · published 1 August 2025

CVE-2025-41375: Limesurvey sql injection vulnerability

Limesurvey · Limesurvey

SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via 'token' parameter in '/index.php' endpoint.

9.3 CVSS 4.0 Critical EPSS 0.63% · top 52.0% CWE-89 · SQL injection
9.3CVSS 4.0 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via 'token' parameter in '/index.php' endpoint.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-41375 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-56422Limesurvey deserialization of untrusted data vulnerabilityA deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.EPSS 0.85%9.8CVE-2022-48008Limesurvey unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.EPSS 1.3%9.8CVE-2019-25019Limesurvey sql injection vulnerabilityLimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.EPSS 1.3%9.8CVE-2020-11455LimeSurvey file manager path traversalLimeSurvey before 4.1.12+200324 contains a path traversal flaw in application/controllers/admin/LimeSurveyFileManager.php. An unauthenticated remote …EPSS 97%analysed9.8CVE-2019-16184Limesurvey csv injection vulnerabilityA CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses th…EPSS 1.7%9.8CVE-2019-9960Limesurvey path traversal vulnerabilityThe downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.EPSS 13%9.8CVE-2018-17057Tecnick tcpdf deserialization of untrusted data vulnerabilityAn issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.EPSS 26%9.3CVE-2008-2570Limesurvey vulnerabilityMultiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2025-41375), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.