Stored Cross-Site Scripting Vulnerability in LimeSurvey Community Edition
CVE-2026-16809
7.2HIGH
What is CVE-2026-16809?
A vulnerability in LimeSurvey Community Edition 7.0.5 allows an authenticated low-privileged user to execute stored malicious JavaScript. This occurs during the survey quota creation process, where the user can insert harmful scripts into the quota message. If exploited, this can lead to unauthorized actions or data leakage affecting survey participants.
Affected Version(s)
LimeSurvey Windows 7.0.5
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Miguel GĂłmez
Fluid Attacks' AI SAST Scanner
