Medium severity5.4OSV Advisory· Published Jan 28, 2026· Updated Jun 17, 2026
CVE-2020-36993
CVE-2020-36993
Description
LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent_id] parameters to execute arbitrary JavaScript in administrative contexts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31.45a, 1.45a_2007-02-24, 1.50_2007-08-06, …+ 2 more
- (no CPE)range: 1.45a, 1.45a_2007-02-24, 1.50_2007-08-06, …
- cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*range: <=4.3.10
- (no CPE)range: <4.3.10
Patches
Vulnerability mechanics
References
4- github.com/LimeSurvey/LimeSurvey/commit/3712854a8fd8d875c67640969a1d54c4d93d3676nvdPatch
- www.exploit-db.com/exploits/48762nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/limesurvey-survey-menu-persistent-cross-site-scriptingnvdThird Party Advisory
- www.limesurvey.orgnvdProduct
News mentions
0No linked articles in our index yet.