CVE-2026-91775
EUVD-2026-8542723.09.2026, 18:17
LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| limesurvey | limesurvey | 7.0.14 | CNA |