🔐 CVE Alert

CVE-2026-102626

UNKNOWN 0.0

LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding.

CWE CWE-79
Vendor limesurvey
Product limesurvey
Published Oct 2, 2026
Last Updated Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for limesurvey limesurvey

Be the first to know when new unknown vulnerabilities affecting limesurvey limesurvey are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

LimeSurvey / LimeSurvey
7.4.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
fluidattacks.com: https://fluidattacks.com/advisories/golden github.com: https://github.com/LimeSurvey/LimeSurvey/ github.com: https://github.com/LimeSurvey/LimeSurvey/commit/32e54f14f0b4ddc2d8144daaabf7e23c3bbfb8e8

Credits

Miguel Gómez Fluid Attacks' AI SAST Scanner