Cross-Site Scripting Vulnerability in LimeSurvey Admin Interface
CVE-2026-91775

7.4HIGH

Key Information:

Vendor

Limesurvey

Vendor
CVE Published:
23 September 2026

What is CVE-2026-91775?

The LimeSurvey application has a security vulnerability where it improperly encodes user-controlled content from specific .lss survey files when displaying import warnings. This flaw enables an attacker to execute malicious scripts in the context of the administrative interface, posing significant risks to the integrity of the application and data. It's critical for users to patch their installations to mitigate this vulnerability.

Affected Version(s)

LimeSurvey Windows 7.0.14

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel GĂłmez
.