CVE-2026-18403: LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB
Published Aug 14, 2026
·Updated
LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list.
Affected Software
1 affected component
Limesurvey LimeSurvey Community Edition=7.0.5
Event History
Aug 14, 2026
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-18403?
CVE-2026-18403 has a risk score of 50, indicating a medium severity level.
2
How do I fix CVE-2026-18403?
To address CVE-2026-18403, update LimeSurvey Community Edition to the latest version that patches the authenticated SQL injection vulnerability.
3
What software is affected by CVE-2026-18403?
CVE-2026-18403 affects LimeSurvey Community Edition 7.0.5.
4
What type of vulnerability is CVE-2026-18403?
CVE-2026-18403 is classified as an SQL Injection vulnerability.
5
When was CVE-2026-18403 published?
CVE-2026-18403 was published on August 14, 2026.