CVE-2026-16809: LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering
Published Aug 26, 2026
·Updated
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message.
This issue affects LimeSurvey: 7.0.5.
Affected Software
1 affected component
Limesurvey LimeSurvey Community Edition=7.0.5
Event History
Aug 26, 2026
CVE Published
via MITRE·09:39 PM
Data Sourced
via MITRE·09:39 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which users can exploit this issue?
An authenticated low-privileged user can exploit it if they are permitted to create and manage their own survey.
2
What input is used to store the malicious script?
The attacker stores malicious JavaScript in a quota message through the survey quota creation workflow.
3
Which deployment version is identified as affected?
The provided information identifies LimeSurvey Community Edition 7.0.5 as affected.