Vulnerability Description
LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list.
Related Weaknesses (CWE)
References
- https://fluidattacks.com/es/advisories/rihanna
- https://github.com/LimeSurvey/LimeSurvey/
- https://github.com/LimeSurvey/LimeSurvey/commit/7735ce31cea1cad087b0c8556cb65a1c
- https://fluidattacks.com/es/advisories/rihanna
FAQ
What is CVE-2026-18403?
CVE-2026-18403 is a documented vulnerability. LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central partic...
How severe is CVE-2026-18403?
CVSS scoring is not yet available for CVE-2026-18403. Check NVD for updates.
Is there a patch for CVE-2026-18403?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.