CVE-2026-63361: LimeSurvey Community Edition 7.0.5+260623 - Reflected XSS in HTML editor popup
Published Aug 14, 2026
·Updated
LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding.
Affected Software
1 affected component
Limesurvey LimeSurvey Community Edition=7.0.5+260623
Event History
Aug 14, 2026
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-63361?
CVE-2026-63361 has a risk rating of 33, indicating a moderate security concern.
2
How do I fix CVE-2026-63361?
To address CVE-2026-63361, update your LimeSurvey Community Edition to version 7.0.6 or later.
3
What type of vulnerability is associated with CVE-2026-63361?
CVE-2026-63361 is classified as an authenticated reflected cross-site scripting (XSS) vulnerability.
4
Which versions of LimeSurvey are affected by CVE-2026-63361?
LimeSurvey Community Edition version 7.0.5 is affected by CVE-2026-63361.
5
What areas of LimeSurvey are impacted by CVE-2026-63361?
CVE-2026-63361 affects the HTML editor popup endpoint within LimeSurvey.