Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding. | |
| Title | LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute | |
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:limesurvey:limesurvey:7.4.0:*:linux:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.4.0:*:macos:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.4.0:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-10-02T18:31:54.975Z
Reserved: 2026-09-29T14:57:45.297Z
Link: CVE-2026-102626
No data.
Status : Deferred
Published: 2026-10-02T18:16:59.433
Modified: 2026-10-02T19:16:39.097
Link: CVE-2026-102626
No data.
OpenCVE Enrichment
Updated: 2026-10-02T19:00:05Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')