Stored Cross-Site Scripting Vulnerability in LimeSurvey Community Edition
CVE-2026-65930
4.8MEDIUM
What is CVE-2026-65930?
LimeSurvey Community Edition 7.0.5 is affected by an authenticated stored cross-site scripting vulnerability within the replacement-fields dialog of the administrative question editor. This vulnerability allows authenticated users to inject malicious scripts, which may execute in the browsers of other users, compromising their data and potentially leading to unauthorized actions within the application.
Affected Version(s)
LimeSurvey 7.0.5
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Miguel GĂłmez
Fluid Attacks' AI SAST Scanner
