SQL Injection Affecting limesurvey/limesurvey package, versions <7.0.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.36% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about SQL Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-LIMESURVEYLIMESURVEY-17660522
  • published27 Jun 2026
  • disclosed9 Jun 2026
  • creditUnknown

Introduced: 9 Jun 2026

CVE-2026-50636  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade limesurvey/limesurvey to version 7.0.1 or higher.

Overview

limesurvey/limesurvey is a FOSS online survey tool on the web.

Affected versions of this package are vulnerable to SQL Injection via the invite_participants and remind_participants API methods, which pass user-supplied token-ID arrays directly into SQL queries without parameterization or input validation. An attacker with the appropriate permission can execute arbitrary SQL commands by injecting crafted input, potentially reading sensitive data such as administrator password hashes, survey responses, and session records, or modifying and deleting database contents. This is only exploitable if the RemoteControl interface (RPCInterface = json/xml) is enabled.

CVSS Base Scores

version 4.0
version 3.1