S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Misconfiguration·Updated Mar 25, 2026

LimeSurvey Default Login Scanner

Targets the LimeSurvey admin login endpoint to identify default username/password combinations, enabling full administrative control over survey data.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
6.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

LimeSurvey is a powerful open-source survey management platform used by organizations to create, distribute, and analyze surveys. It supports various question types, survey logic, and user roles, making it ideal for market research, academic studies, and customer feedback. Administrators manage surveys, users, and permissions through a web-based interface.

The vulnerability arises when administrators fail to change default credentials after installation. LimeSurvey ships with known default usernames and passwords (e.g., admin/password). Attackers can exploit this oversight to gain unauthorized access to the admin panel, bypassing authentication controls.

This scanner specifically targets the LimeSurvey admin login endpoint (e.g., /admin/authentication/sa/login) and attempts authentication using common default credential pairs. It checks for successful login responses, indicating the presence of default credentials.

If exploited, an attacker gains full administrative access to the LimeSurvey instance. They can modify surveys, export sensitive respondent data, delete surveys, or inject malicious code. This can lead to data breaches, reputational damage, and compliance violations.

Solution Advice
  • Immediately change all default administrator credentials to strong, unique passwords.
  • Enforce password complexity policies requiring minimum length and character variety.
  • Enable two-factor authentication (2FA) for all admin accounts.
  • Regularly audit user accounts and remove unused or unnecessary admin privileges.
  • Implement IP whitelisting for admin login pages to restrict access.
  • Monitor login attempts and set up alerts for repeated failed logins.
  • Keep LimeSurvey updated to the latest version to benefit from security patches.
  • Conduct periodic security scans to detect default credentials and other misconfigurations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.