LimeSurvey 社区版 7.0.5 在“调查菜单项”管理页面中存在一个存储型跨站脚本(Stored XSS)漏洞。拥有全局 权限的认证用户,可以创建包含攻击者可控数据的调查菜单项。该数据被存储在 字段中,随后在未进行上下文适当编码的情况下,被插入到 HTML 属性(带单引号)中。 此问题影响 LimeSurvey 7.0.5 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LimeSurvey | LimeSurvey | 7.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63360 | 7.4 HIGH | LimeSurvey Community Edition 7.0.5 - Reflected XSS in user activation confirmation endpoin |
| CVE-2026-16809 | 7.2 HIGH | LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering |
| CVE-2026-65930 | 4.8 MEDIUM | LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields |
No comments yet