CVE-2026-102626: LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute
An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the datemin attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding.
Affected Software
Event History
Frequently Asked Questions
Who can introduce the malicious value?
An authenticated LimeSurvey Community Edition user needs the global Surveys: create permission to store a JavaScript-breaking value in the Date/Time question's date_min attribute.
When does the stored payload execute?
The payload is rendered when another user views the affected Date/Time question. The vulnerable application places the stored date_min value in a single-quoted inline JavaScript literal without JavaScript-context encoding.
How can administrators identify potentially affected surveys?
Review Date/Time questions created or editable by users with the global Surveys: create permission, focusing on date_min attribute values that contain characters capable of breaking out of a single-quoted JavaScript string.