View Issue Details

This issue affects 2 person(s).
 12
IDProjectCategoryView StatusLast Update
20619Feature requestsUsability/user experiencepublic2026-08-08 13:23
Reportermo2025 Assigned To 
PrioritynoneSeverityfeature 
Status newResolutionopen 
Summary20619: Security update available - although LimeSurvey is updated to the latest 6.x version
Description

We currently have two recent versions, one in the 6.x line and one in the 7.x line. Both are considered stable.
Since we cannot switch to the 7.x version anytime soon, but security updates are available for the 6.x version, the message “Security update available” should only be displayed if not all security patches for the 6.x version have been installed.

This leads to uncertainty and unease among users, as this gives the impression that LimeSurvey is being operated with security vulnerabilities, while at the same time handling sensitive data (surveys).

TagsNo tags attached.
Bug heat12
Story point estimate0
Users affected %0

Users monitoring this issue

arpsh

Activities

mo2025

mo2025

2026-07-24 14:00

reporter   ~85271

What's strange is:
It seems that LimeSurvey behaves differently depending on whether it was installed or updated via Git or from a ZIP file:
I’ve attached two screenshots as notes; one shows the status of the production system after the update, with a notification that a security update is available, while the other does not display that notification.

Both versions are 6.17.12.

When I click on “Security update available” in the production system, I see the content of the third screenshot: that version 7.0.6 is available.

c_schmitz

c_schmitz

2026-08-04 09:09

administrator   ~85312

We do not support installations from Github. That's why it is not possible to update them by Comfortupdate.

mo2025

mo2025

2026-08-04 09:31

reporter   ~85313

Hi Christian,

Please excuse me—I didn't express myself clearly.

I performed the update on our production system using the ZIP file (version 6.17.12) that I downloaded manually from https://community.limesurvey.org/downloads/.

At that time, this was the latest version for the 6.x series.
Nevertheless, a message appeared at the top of the screen indicating that a newer version was available.

Since I like the project, I thought I could support it by helping to fix a possible bug, so I installed Limesurvey from the Git repository on my local machine in a Docker container to investigate the situation more closely.

The issue did not occur there. That’s what I was trying to point out with my reference to Git.

===
What will I do next? I’m going to update from 6.17.12 to 6.17.13 and see if I still get the notification. If the notification no longer appears, everything is fine and the ticket can be closed.

If the error persists, it would be interesting to know whether other users are experiencing it as well.

Best,
Markus

mo2025

mo2025

2026-08-08 13:23

reporter   ~85408

No, unfortunately, the situation remains the same:
When I update to the latest version of the 6.x series, I still see a notification saying there is a “security update available.”

My guess is that the system is checking to see if there is a newer version available in general and is mistaking the 7.x version for it. Could that be the case?

limesurvey-falscher-hinweis.png (40,049 bytes)   
limesurvey-falscher-hinweis.png (40,049 bytes)   

Issue History

Date Modified Username Field Change
2026-07-24 11:11 mo2025 New Issue
2026-07-24 14:00 mo2025 Note Added: 85271
2026-07-24 14:00 mo2025 File Added: Screenshot 2026-07-24 135122.png
2026-07-24 14:00 mo2025 File Added: Screenshot 2026-07-24 135418.png
2026-07-24 14:00 mo2025 File Added: Screenshot 2026-07-24 135912.png
2026-07-24 14:00 mo2025 Bug heat 0 => 2
2026-07-24 15:09 arpsh Issue Monitored: arpsh
2026-07-24 15:09 arpsh Bug heat 2 => 4
2026-07-24 15:10 guest Bug heat 4 => 10
2026-08-04 09:09 c_schmitz Note Added: 85312
2026-08-04 09:09 c_schmitz Bug heat 10 => 12
2026-08-04 09:31 mo2025 Note Added: 85313
2026-08-08 13:23 mo2025 Note Added: 85408
2026-08-08 13:23 mo2025 File Added: limesurvey-falscher-hinweis.png