LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface. | |
| Title | LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings | |
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:limesurvey:limesurvey:7.0.14:*:linux:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.0.14:*:macos:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.0.14:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-09-23T17:44:18.848Z
Reserved: 2026-09-15T01:05:55.848Z
Link: CVE-2026-91775
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses