Please report (suspected) security vulnerabilities to support@limesurvey.org or create a bug report and mark it as private. Marking it as private will make the bug report visible to only users who have access.
You will receive a response from us within 48 hours. If the issue is confirmed, we will release a patch as soon as possible depending on complexity but historically within a few days.