CVE-2025-70797
Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via
Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] parameters.
MEDIUM · CVSS 6.1
EPSS 0.00077
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0