LOWVulnerability

CVE-2026-63361

LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding.

Properties

cve_id
CVE-2026-63361
published_at
2026-08-14T18:18:53.650
last_modified
2026-08-26T21:16:39.970

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-63361 — Ninja Signal Threat Intelligence | Ninja Signal