Description
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message.

This issue affects LimeSurvey: 7.0.5.
Published: 2026-08-26
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting in LimeSurvey 7.0.5
Action: Patch
AI Analysis

Impact

The flaw permits an authenticated low‑privileged user, such as a survey creator, to embed JavaScript in a quota message. When respondents view that message, the payload runs in their browsers in the context of the survey page, allowing the attacker to execute arbitrary client‑side code.

Affected Systems

LimeSurvey Community Edition 7.0.5 on Linux, macOS, and Windows. The affected product is the standard LimeSurvey application for these operating systems.

Risk and Exploitability

The CVSS score is 7.2, indicating high severity. The EPSS score is not available, so exploitation frequency is unknown. The vulnerability is not listed in CISA KEV. It can be exploited by any user with permission to edit a survey’s quota messages; the attacker stores malicious JavaScript, which is then executed when respondents load the affected survey.

Generated by OpenCVE AI on August 26, 2026 at 23:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update LimeSurvey to the latest version that contains the stored XSS fix.
  • Restrict quota message editing rights to administrative roles until the patch is applied.
  • Implement server‑side validation and sanitization of quota message input to strip executable content.

Generated by OpenCVE AI on August 26, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects LimeSurvey: 7.0.5.
Title LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering
First Time appeared Limesurvey
Limesurvey limesurvey
Weaknesses CWE-79
CPEs cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:linux:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:macos:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:windows:*:*:*:*:*
Vendors & Products Limesurvey
Limesurvey limesurvey
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Limesurvey Limesurvey
cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-08-27T18:30:59.918Z

Reserved: 2026-07-23T21:22:05.734Z

Link: CVE-2026-16809

cve-icon Vulnrichment

Updated: 2026-08-27T18:30:54.383Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T22:16:23.160

Modified: 2026-08-28T15:31:31.210

Link: CVE-2026-16809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T02:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')