πŸ” CVE Alert

CVE-2026-92730

UNKNOWN 0.0

LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page.

CWE CWE-79
Vendor limesurvey
Product limesurvey
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for limesurvey limesurvey

Be the first to know when new unknown vulnerabilities affecting limesurvey limesurvey are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

LimeSurvey / LimeSurvey
7.0.14

References

NVD β†— CVE.org β†— EPSS Data β†—
fluidattacks.com: https://fluidattacks.com/es/advisories/camisa github.com: https://github.com/LimeSurvey/LimeSurvey/ github.com: https://github.com/LimeSurvey/LimeSurvey/commit/0523de7bbb0282af33a0bf9e08a1fc6333ae6851

Credits

Miguel GΓ³mez