Vulnerability Description
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects LimeSurvey: 7.0.5.
Related Weaknesses (CWE)
References
- https://fluidattacks.com/es/advisories/wellerman
- https://github.com/LimeSurvey/LimeSurvey
- https://fluidattacks.com/es/advisories/wellerman
FAQ
What is CVE-2026-16809?
CVE-2026-16809 is a documented vulnerability. LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own ...
How severe is CVE-2026-16809?
CVSS scoring is not yet available for CVE-2026-16809. Check NVD for updates.
Is there a patch for CVE-2026-16809?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.