CVE-2026-91775: LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings
Published Sep 23, 2026
·Updated
LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.
Affected Software
1 affected component
Limesurvey LimeSurvey Community Edition=7.0.14
Event History
Sep 23, 2026
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Administrative users who import a crafted .lss survey file are exposed, because the malicious content is rendered in survey-import warnings within the administrative interface.
2
What does an attacker need to exploit it?
The attacker needs to supply a crafted .lss survey file and have it imported by an administrative user. The available information does not establish that the issue is reachable without an import action.
3
How can an organization reduce risk before applying a fix?
Do not import untrusted .lss survey files, and restrict survey-import capability to trusted administrative users. Review the source of any survey file before importing it.