HIGH 7.4 NVD
CVE-2026-91775
LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administr
LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.
References
- https://fluidattacks.com/advisories/alone
- https://github.com/LimeSurvey/LimeSurvey
- https://github.com/LimeSurvey/LimeSurvey/commit/c96db8093e852eb8b1a2ebbb32478d6fb34cb651
- https://fluidattacks.com/advisories/alone
This high severity vulnerability with a CVSS score of 7.4 was published on 2026-09-23 via NVD.
vulnfeed aggregates 12908 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.