CVE-2026-92730: LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name
Published Sep 23, 2026
·Updated
LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page.
Affected Software
1 affected component
Limesurvey LimeSurvey Community Edition=7.0.14
Event History
Sep 23, 2026
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Administrators who use the survey-participant CSV import function in LimeSurvey Community Edition 7.0.14 are exposed when viewing the import result page for a crafted CSV file.
2
What does an attacker need to exploit it?
An attacker needs a CSV import to contain an invalid attribute column name carrying script content, and an administrator must import that file and view the resulting import result page.