Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list. | |
| Title | LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB | |
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:linux:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:macos:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-08-14T19:31:02.423Z
Reserved: 2026-07-30T15:42:19.090Z
Link: CVE-2026-18403
Updated: 2026-08-14T19:30:54.955Z
Status : Received
Published: 2026-08-14T19:17:17.343
Modified: 2026-08-14T20:16:51.613
Link: CVE-2026-18403
No data.
OpenCVE Enrichment
Updated: 2026-08-14T20:45:03Z
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')