LimeSurvey Community Edition 7.0.5+260623 contains an...
High severity
Unreviewed
Published
Aug 27, 2026
to the GitHub Advisory Database
•
Updated Aug 27, 2026
Description
Published by the National Vulnerability Database
Aug 26, 2026
Published to the GitHub Advisory Database
Aug 27, 2026
Last updated
Aug 27, 2026
LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding.
This issue affects LimeSurvey: 7.0.5.
References