Description LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model. Remediation References CVE-2019-25019 Related Vulnerabilities PHP NULL Pointer Dereference Vulnerability (CVE-2025-6491) WordPress Plugin Anti-Splog Cross-Site Scripting (2.1.7) Jenkins Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-21605) Sqlite Out-of-bounds Read Vulnerability (CVE-2017-10989) WordPress Improper Input Validation Vulnerability (CVE-2013-5738) Severity Critical Classification CVE-2019-25019 CWE-138 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities