LimeSurvey Community Edition 7.0.5+260623 was disclosed with an authenticated reflected cross-site scripting flaw tracked as CVE-2026-63361 in the HTML editor popup endpoint. The vulnerability affects the text and name query parameters, which were filtered with a blacklist-based sanitizer but then rendered without proper context-aware output encoding, allowing attacker-controlled input to be reflected into HTML and script contexts. The issue is classified as CWE-79 and impacts LimeSurvey deployments on Windows, macOS, and Linux.
A security fix was committed in the LimeSurvey GitHub repository under issue #20652, updating application/views/admin/htmleditor/pop_editor_view.php to encode user-controlled values before output. The patch replaces raw rendering of variables including $sFieldText, $sFieldName, $sControlIdEna, and $sControlIdDis with CHtml::encode and CJavaScript::encode, closing the reflected XSS path in the popup rendering and related DOM access logic.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On August 14, 2026, CVE-2026-63361 was newly received for an authenticated reflected XSS vulnerability affecting LimeSurvey Community Edition 7.0.5 on Windows, macOS, and Linux. The flaw involves the HTML editor popup endpoint rendering the text and name parameters without proper context-aware output encoding.
On August 13, 2026, LimeSurvey committed a fix for issue #20652, a reflected XSS vulnerability in the HTML editor popup endpoint. The patch added proper HTML and JavaScript output encoding in pop_editor_view.php and was recorded as commit a8993bfd05c4a11255b8400ed9c41a2c22e93aa4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcefluidattacks.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.