← Back to CVE List
CVE-2026-102626NVD
Vulnerability Summary
An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding.
CVSS v4.0 Base Metrics — Score 7.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredLow
User InteractionActive
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)None
Confidentiality (Subsequent System)Low
Integrity (Subsequent System)Low
Availability (Subsequent System)None
Affected & Patched Versions
- LimeSurvey LimeSurvey >= 7.4.0
Not provided by cveorg for this CVE.