Information Exposure Affecting limesurvey/limesurvey package, versions >=2.2.5, <6.15.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-LIMESURVEYLIMESURVEY-14075609
  • published21 Nov 2025
  • disclosed20 Nov 2025
  • creditJulen Garrido Estevez

Introduced: 20 Nov 2025

CVE-2025-41076  (opens in a new tab)
CWE-209  (opens in a new tab)

How to fix?

Upgrade limesurvey/limesurvey to version 6.15.0 or higher.

Overview

limesurvey/limesurvey is a FOSS online survey tool on the web.

Affected versions of this package are vulnerable to Information Exposure via the handling of malformed session cookies. An attacker can obtain sensitive internal backend information, such as framework details, database engine, table names, primary keys, and fragments of session data, by sending a specially crafted session cookie that triggers a server error 500.

References

CVSS Base Scores

version 4.0
version 3.1