๐Ÿ” CVE Alert

CVE-2026-18403

UNKNOWN 0.0

LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list.

CWE CWE-89
Vendor limesurvey
Product limesurvey
Published Aug 14, 2026
Last Updated Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for limesurvey limesurvey

Be the first to know when new unknown vulnerabilities affecting limesurvey limesurvey are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

LimeSurvey / LimeSurvey
7.0.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
fluidattacks.com: https://fluidattacks.com/es/advisories/rihanna github.com: https://github.com/LimeSurvey/LimeSurvey/ github.com: https://github.com/LimeSurvey/LimeSurvey/commit/7735ce31cea1cad087b0c8556cb65a1c09e29cbd

Credits

Miguel Gomez Fluid Attacks' AI SAST Scanner