← Vulnerability feed

Vulnerability record · CVE-2025-56421 · published 10 March 2026

CVE-2025-56421: Limesurvey sql injection vulnerability

Limesurvey · Limesurvey

SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.

7.5 CVSS 3.1 High EPSS 0.47% · top 62.0% CWE-89 · SQL injection
7.5CVSS 3.1 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
5 Jul 2026Last modified by NVD

Description

SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-56421 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-56422Limesurvey deserialization of untrusted data vulnerabilityA deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.EPSS 0.85%9.8CVE-2022-48008Limesurvey unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.EPSS 1.3%9.8CVE-2019-25019Limesurvey sql injection vulnerabilityLimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.EPSS 1.3%9.8CVE-2020-11455LimeSurvey file manager path traversalLimeSurvey before 4.1.12+200324 contains a path traversal flaw in application/controllers/admin/LimeSurveyFileManager.php. An unauthenticated remote …EPSS 97%analysed9.8CVE-2019-16184Limesurvey csv injection vulnerabilityA CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses th…EPSS 1.7%9.8CVE-2019-9960Limesurvey path traversal vulnerabilityThe downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.EPSS 13%9.8CVE-2018-17057Tecnick tcpdf deserialization of untrusted data vulnerabilityAn issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.EPSS 26%9.3CVE-2025-41375Limesurvey sql injection vulnerabilitySQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via '…EPSS 0.63%

Source: NIST National Vulnerability Database (record CVE-2025-56421), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.