LimeSurvey 社区版 7.0.5+260623 在用户激活确认端点存在一个经过身份验证的反射型跨站脚本(Reflected Cross-Site Scripting, XSS)漏洞。其中, 查询参数被直接复制到响应中,并插入到一个隐藏输入字段的属性中,但未进行 HTML 属性编码。 该问题影响 LimeSurvey 版本:7.0.5。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LimeSurvey | LimeSurvey | 7.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15973 | 8.4 HIGH | LimeSurvey 7.0.5 - Stored XSS in Survey Menu Entries |
| CVE-2026-16809 | 7.2 HIGH | LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering |
| CVE-2026-65930 | 4.8 MEDIUM | LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields |
No comments yet