Authenticated Reflected XSS in LimeSurvey Community Edition
CVE-2026-63361
8.5HIGH
What is CVE-2026-63361?
LimeSurvey Community Edition version 7.0.5 has a vulnerability within its HTML editor popup endpoint that allows for authenticated reflected cross-site scripting. This occurs because user-supplied input in the text and name query parameters is inadequately sanitized through a blacklist approach and then outputted without proper encoding for the context. This flaw can lead to the injection of malicious scripts, potentially compromising user session and data integrity.
Affected Version(s)
LimeSurvey Windows 7.0.5
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Miguel Gomez
Fluid Attacks' AI SAST Scanner
