Stored Cross-Site Scripting Vulnerability in LimeSurvey Community Edition
CVE-2026-65930

4.8MEDIUM

Key Information:

Vendor

Limesurvey

Vendor
CVE Published:
26 August 2026

What is CVE-2026-65930?

LimeSurvey Community Edition 7.0.5 is affected by an authenticated stored cross-site scripting vulnerability within the replacement-fields dialog of the administrative question editor. This vulnerability allows authenticated users to inject malicious scripts, which may execute in the browsers of other users, compromising their data and potentially leading to unauthorized actions within the application.

Affected Version(s)

LimeSurvey 7.0.5

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel GĂłmez
Fluid Attacks' AI SAST Scanner
.