---
id: CVE-2026-102626
title: "An authenticated LimeSurvey Community Edition 7.4.0\_user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question"
summary: "An authenticated LimeSurvey Community Edition 7.4.0\_user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question,…"
severity: high
cvss: 7.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N'
cwe:
  - CWE-79
vendor: LimeSurvey
product: LimeSurvey
affected:
  - LimeSurvey 7.4.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:16:59.677'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102626'
references:
  - url: 'https://fluidattacks.com/advisories/golden'
    label: help@fluidattacks.com
  - url: 'https://github.com/LimeSurvey/LimeSurvey/'
    label: help@fluidattacks.com
  - url: >-
      https://github.com/LimeSurvey/LimeSurvey/commit/32e54f14f0b4ddc2d8144daaabf7e23c3bbfb8e8
    label: help@fluidattacks.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T18:25:05.829Z'
---

## Overview

An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
