CVE-2026-102626
LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding.
| CWE | CWE-79 |
| Vendor | limesurvey |
| Product | limesurvey |
| Published | Oct 2, 2026 |
| Last Updated | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for limesurvey limesurvey
Be the first to know when new unknown vulnerabilities affecting limesurvey limesurvey are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
LimeSurvey / LimeSurvey
7.4.0
References
Credits
Miguel Gómez Fluid Attacks' AI SAST Scanner