Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102626— LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute

Quick assessment

Affected
LimeSurvey LimeSurvey
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 LimeSurvey Community Edition 7.4.0 中,拥有“全局问卷:创建”权限的已认证用户可以在日期/时间类型问题的 属性中存储一个破坏 JavaScript 语法的值。当其他用户渲染受影响的问卷时,LimeSurvey 会将该存储的值直接插入到一个单引号包裹的内联 JavaScript 字符串字面量中,且未进行 JavaScript 上下文编码。

CVSS 7.2 · High EPSS 0.27% · P17

Affected Version Matrix 1

VendorProduct Version RangeStatus
LimeSurvey LimeSurvey 7.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102626

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute
Source: CVE Program / CVE List V5
Vulnerability Description
An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
LimeSurvey LimeSurvey 7.4.0 -

II. Public POCs for CVE-2026-102626

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102626

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-102626 (1)

Vendor Advisories for CVE-2026-102626 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102626

No comments yet


Leave a comment