CVE-2026-16809EPSS p14.1%
CVE-2026-16809CVE-2026-16809
Description
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message.
This issue affects LimeSurvey: 7.0.5.
Scoring
| EPSS | 0.24% probability of exploitation · percentile 14.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-28 |