LimeSurvey

9 known vulnerabilities in LimeSurvey, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-102626 CVSS 7.2 high An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value…
  • CVE-2026-97685 CVSS 7.1 high An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while…
  • CVE-2026-92730 CVSS 7.4 high LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV…
  • CVE-2026-91775 CVSS 7.4 high LimeSurvey Community Edition 7.0.14 fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying…
  • CVE-2026-65931 CVSS 5.1 medium LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation…
  • CVE-2026-65930 CVSS 4.8 medium LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog…
  • CVE-2026-63360 CVSS 7.4 high LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation…
  • CVE-2026-16809 CVSS 7.2 high LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An…
  • CVE-2026-15973 CVSS 8.4 high LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An…