A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
https://www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-released