CVE-2025-41376
Severity CVSS v4.0:
MEDIUM
Type:
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
Publication date:
01/08/2025
Last modified:
30/01/2026
Description
CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid//token/fwyfw%0d%0aCookie:%20POC'.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:* | 2.65.1 (including) | 3.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



