CVE-2026-18403: Limesurvey

Medium severity, CVSS 6.0. EPSS: 0.4% chance of exploitation in the next 30 days.

LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list.

Affected products

Published 2026-08-14. Last modified 2026-08-28.