


Perceptive Security
SOC/SIEM Consultancy

SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.
Published:
9 maart 2026 om 23:00:00
Alert date:
10 maart 2026 om 20:02:32
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A SQL Injection vulnerability has been identified in LimeSurvey versions before v.6.15.4+250710. The vulnerability allows remote attackers to obtain sensitive information from the database. This represents a significant security risk as it enables unauthorized access to potentially confidential survey data and user information. Organizations using affected versions of LimeSurvey should upgrade to the patched version immediately to prevent potential data exposure.
Technical details
Mitigation steps:
Affected products:
LimeSurvey
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-56421
http://limesurvey.com
https://github.com/hongancalif/security-advisories/blob/main/CVE-2025-56421.md
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
