Cross-Site Scripting Vulnerability in LimeSurvey Admin Interface
CVE-2026-91775
7.4HIGH
What is CVE-2026-91775?
The LimeSurvey application has a security vulnerability where it improperly encodes user-controlled content from specific .lss survey files when displaying import warnings. This flaw enables an attacker to execute malicious scripts in the context of the administrative interface, posing significant risks to the integrity of the application and data. It's critical for users to patch their installations to mitigate this vulnerability.
Affected Version(s)
LimeSurvey Windows 7.0.14
