CVE-2026-18403

Source
https://cve.org/CVERecord?id=CVE-2026-18403
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18403.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18403
Published
2026-08-14T18:33:31.017Z
Modified
2026-08-16T03:48:28.866487050Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB
Details

LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18403.json",
    "cna_assigner": "Fluid Attacks"
}
References

Affected packages

Git / github.com/limesurvey/limesurvey

Affected ranges

Type
GIT
Repo
https://github.com/limesurvey/limesurvey
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.0.5"
        },
        {
            "last_affected": "7.0.5"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

7.*
7.0.5
7.0.5+260623
7.0.6+260722
7.0.7+260729
7.0.8+260806
7.0.9+260812

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18403.json"