Description
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message.

This issue affects LimeSurvey: 7.0.5.
Published: 2026-08-26
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw permits an authenticated low‑privileged user, such as a survey creator, to embed JavaScript in a quota message. When respondents view that message, the payload runs in their browsers in the context of the survey page, allowing the attacker to execute arbitrary client‑side code.

Affected Systems

LimeSurvey Community Edition 7.0.5 on Linux, macOS, and Windows. The affected product is the standard LimeSurvey application for these operating systems.

Risk and Exploitability

The CVSS score is 7.2, indicating high severity. The EPSS score is not available, so exploitation frequency is unknown. The vulnerability is not listed in CISA KEV. It can be exploited by any user with permission to edit a survey’s quota messages; the attacker stores malicious JavaScript, which is then executed when respondents load the affected survey.

Generated by OpenCVE AI on August 26, 2026 at 23:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update LimeSurvey to the latest version that contains the stored XSS fix.
  • Restrict quota message editing rights to administrative roles until the patch is applied.
  • Implement server‑side validation and sanitization of quota message input to strip executable content.

Generated by OpenCVE AI on August 26, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects LimeSurvey: 7.0.5.
Title LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering
First Time appeared Limesurvey
Limesurvey limesurvey
Weaknesses CWE-79
CPEs cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:linux:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:macos:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:windows:*:*:*:*:*
Vendors & Products Limesurvey
Limesurvey limesurvey
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Limesurvey Limesurvey
cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-08-26T21:39:34.719Z

Reserved: 2026-07-23T21:22:05.734Z

Link: CVE-2026-16809

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T22:16:23.160

Modified: 2026-08-26T22:16:23.160

Link: CVE-2026-16809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:30:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')