CVE-2026-92730 Overview
CVE-2026-92730 is a reflected cross-site scripting (XSS) vulnerability [CWE-79] in LimeSurvey Community Edition 7.0.14. The flaw resides in the administrative survey-participant CSV import result page. When an administrator imports a crafted CSV file, unsanitized attribute field names are reflected back into the response and executed in the browser context.
Successful exploitation requires user interaction from an authenticated administrator. An attacker who convinces an admin to import a malicious CSV can hijack the session, perform actions as the administrator, or pivot to further compromise of the LimeSurvey instance.
Critical Impact
Attackers can execute arbitrary JavaScript in the browser of an authenticated LimeSurvey administrator, leading to session compromise and administrative account takeover.
Affected Products
- LimeSurvey Community Edition 7.0.14
- LimeSurvey administrative token/participant import interface (application/controllers/admin/Tokens.php)
- LimeSurvey deployments prior to commit 0523de7
Discovery Timeline
- 2026-09-23 - CVE-2026-92730 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-92730
Vulnerability Analysis
The vulnerability is a reflected XSS in the CSV import flow used to add survey participants. When a LimeSurvey administrator uploads a CSV file, the application parses column headers from the first line and compares them against known attribute field names. If a header beginning with attribute_ is not recognized and the showwarningtoken warning is enabled, the header value is added to an invalid-attribute list and rendered back into the admin response page.
Because the header value was written into the response without HTML encoding, an attacker-controlled CSV header containing JavaScript payloads executes when the administrator views the import result. The attack requires the administrator to open a crafted CSV, satisfying the user interaction requirement in the CVSS vector.
Root Cause
The root cause is missing output encoding in application/controllers/admin/Tokens.php. User-supplied CSV header values were pushed directly into $aInvalideAttrFieldName and later rendered in HTML without escaping. The patch wraps the value with CHtml::encode() before storage, ensuring HTML-special characters are neutralized at render time.
Attack Vector
An attacker crafts a CSV file whose header row contains an attribute_ column name with an embedded XSS payload. The attacker delivers the file to a LimeSurvey administrator through phishing or an internal share. When the administrator imports the file through the participants panel, the reflected payload executes in the administrator's authenticated session.
}
// Attribute not in list
if (strpos($aFirstLine[$index], 'attribute_') !== false and !in_array($aFirstLine[$index], $aAttrFieldNames) and Yii::app()->request->getPost('showwarningtoken')) {
- $aInvalideAttrFieldName[] = $aFirstLine[$index];
+ $aInvalideAttrFieldName[] = CHtml::encode($aFirstLine[$index]);
}
}
//compare attributes with source csv
Source: GitHub LimeSurvey Commit 0523de7
Detection Methods for CVE-2026-92730
Indicators of Compromise
- CSV files uploaded to the LimeSurvey participant import endpoint containing header cells with <script>, onerror=, onload=, or other HTML/JavaScript syntax.
- Web server access logs showing POST requests to the admin Tokens controller import action from unusual sources or at unusual times.
- Administrator browser sessions initiating unexpected outbound requests immediately after a CSV import.
Detection Strategies
- Inspect uploaded CSV files at the web application firewall (WAF) or file-scanning layer for HTML tag patterns in header rows.
- Review LimeSurvey audit and web server logs for administrator activity that correlates with participant import events, especially those returning warning pages.
- Correlate administrator session activity with subsequent unusual admin actions such as user creation, permission changes, or data exports.
Monitoring Recommendations
- Enable and centralize LimeSurvey admin action logging and forward events to a security monitoring platform.
- Monitor for browser console errors and Content Security Policy (CSP) violations originating from /admin/tokens paths.
- Alert on anomalous outbound HTTP requests from administrator workstations following CSV import operations.
How to Mitigate CVE-2026-92730
Immediate Actions Required
- Upgrade LimeSurvey Community Edition to a version that includes commit 0523de7bbb0282af33a0bf9e08a1fc6333ae6851 or later.
- Restrict administrative interface access to trusted networks or VPN users only.
- Instruct administrators not to import CSV files received from untrusted or unverified sources.
Patch Information
The LimeSurvey maintainers addressed the vulnerability in commit 0523de7bbb0282af33a0bf9e08a1fc6333ae6851, which wraps the invalid attribute field name with CHtml::encode() before rendering. Details are available in the Fluid Attacks Security Advisory and the GitHub LimeSurvey Commit.
Workarounds
- Disable the showwarningtoken option in survey settings to prevent the vulnerable rendering path from executing.
- Enforce a strict Content Security Policy on the LimeSurvey admin interface to block inline script execution.
- Sanitize or validate CSV files with an external tool before importing into the LimeSurvey participants panel.
# Example strict CSP header for the LimeSurvey admin interface (nginx)
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'" always;
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
