Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:limesurvey:limesurvey:6.15.20:251021:*:*:*:*:*:* |
Fri, 10 Apr 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting in LimeSurvey Box Parameters Allows Remote Code Execution |
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
Thu, 09 Apr 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 09 Apr 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] parameters. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-09T21:21:54.090Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70797
No data.
Status : Analyzed
Published: 2026-04-09T18:16:42.547
Modified: 2026-04-16T19:01:01.583
Link: CVE-2025-70797
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:33:09Z