CVE-2026-91775EPSS p29.7%

CVE-2026-91775CVE-2026-91775

Description

LimeSurvey Community Edition 7.0.14 fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.

Scoring

EPSS0.38% probability of exploitation · percentile 29.7% · 2026-10-05T12:00:23Z
Last modified2026-10-02
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.