HIGH 8.5 NVD
CVE-2026-63361
LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name q
LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding.
References
- https://fluidattacks.com/es/advisories/mercedes
- https://github.com/LimeSurvey/LimeSurvey
- https://github.com/LimeSurvey/LimeSurvey/commit/a8993bfd05c4a11255b8400ed9c41a2c22e93aa4
- https://fluidattacks.com/es/advisories/mercedes
This high severity vulnerability with a CVSS score of 8.5 was published on 2026-08-14 via NVD.
vulnfeed aggregates 10939 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.