Authenticated Reflected XSS in LimeSurvey Community Edition
CVE-2026-63361

8.5HIGH

Key Information:

Vendor

Limesurvey

Vendor
CVE Published:
14 August 2026

What is CVE-2026-63361?

LimeSurvey Community Edition version 7.0.5 has a vulnerability within its HTML editor popup endpoint that allows for authenticated reflected cross-site scripting. This occurs because user-supplied input in the text and name query parameters is inadequately sanitized through a blacklist approach and then outputted without proper encoding for the context. This flaw can lead to the injection of malicious scripts, potentially compromising user session and data integrity.

Affected Version(s)

LimeSurvey Windows 7.0.5

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel Gomez
Fluid Attacks' AI SAST Scanner
.