Junglewise Threat Intelligence

CVE-2025-56422: LimeSurvey unsafe deserialization remote code execution

CVE-2025-56422 · Severity: critical · CVSS 9.8 · Published 2026-03-10

Technologies: LimeSurvey. Vendors: LimeSurvey.

Executive brief

LimeSurvey, a popular open-source online survey application, contains a critical security flaw that allows unauthorized individuals to take control of the server. By sending a specially crafted request, an attacker can execute their own commands, potentially leading to the theft of survey data, modification of results, or a complete shutdown of the service. Organizations using LimeSurvey should update to the latest version immediately to protect their data and operations.

Technical details

A critical deserialization vulnerability (CWE-502) exists in LimeSurvey versions prior to 6.15.0+250623. The application improperly handles user-controlled input during the deserialization process, allowing an attacker to provide a specially crafted serialized object. This can be exploited remotely without authentication to trigger arbitrary code execution within the application context. The vulnerability is reachable over the network and poses a high risk to confidentiality, integrity, and availability. Users are advised to upgrade to version 6.15.0+250623 or later to mitigate this risk.

Affected products

  • LimeSurvey LimeSurvey < 6.15.0+250623

Timeline

  • 2026-03-10: advisory: Initial disclosure of CVE-2025-56422
  • 2026-03-10: patched: Fix released in version 6.15.0+250623

References

Related threats