PT-2026-5119 · Unknown · Limesurvey

Matthew Aberegg

·

Published

2026-01-28

·

Updated

2026-01-28

·

CVE-2020-36993

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LimeSurvey versions 4.3.10 and earlier
Description LimeSurvey is affected by a stored cross-site scripting issue in the Survey Menu functionality within the administration panel. An attacker can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent id] parameters. Successful exploitation allows the execution of arbitrary JavaScript in administrative contexts.
Recommendations Versions prior to 4.3.10 are vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-36993

Affected Products

Limesurvey