Junglewise Threat Intelligence

CVE-2026-65930: LimeSurvey Community Edition stored XSS in replacement-fields dialog

CVE-2026-65930 · Severity: info · Published 2026-08-26

Executive brief

LimeSurvey Community Edition is an open-source survey and form creation platform. Version 7.0.5 contains a stored cross-site scripting vulnerability in the administrative question editor's replacement-fields dialog that allows authenticated administrators to inject malicious scripts, potentially compromising survey data, administrator accounts, or survey respondent information.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the replacement-fields dialog component of LimeSurvey's administrative question editor. The vulnerability requires authentication as an administrator to exploit. An attacker with administrative credentials can inject malicious JavaScript into the replacement-fields dialog, which is then stored and executed in the browsers of other administrators or users who view the affected questions. This allows session hijacking, credential theft, or manipulation of survey content and responses.

Affected products

  • LimeSurvey Community Edition 7.0.5

References