CVE-2026-18403Disclosure

LOWCVSS 6.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-14); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-14: 1Mentions · 2026-09-15: 1Technical Details · 2026-08-14: 108-1409-15
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Fluid Attacks@fluidattacks
    Disclosure

    🚨New zero-day in LimeSurvey | Detected by our AI SAST scanner and disclosed by Miguel Gómez. As a #CNA, we assigned the ID CVE-2026-18403. Details: 🔗https://fluidattacks.com/advisories/rihanna. We have announced 271 #CVEs to this date: 🔗 https://fluidattacks.com/advisories/. https://t.co/1FO3YRjsTi

    Post summary

    The tweet discloses a newly discovered zero‑day vulnerability in LimeSurvey, assigned CVE‑2026‑18403, with a link to detailed advisory information; it does not mention a PoC, exploit, patch, or active exploitation.

    1001191
    901 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-18403 Authenticated SQL Injection in LimeSurvey Community Edition 7.0.5 CPDB Workflow https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-18403

    Post summary

    The text announces an authenticated SQL injection vulnerability (CVE‑2026‑18403) affecting LimeSurvey Community Edition 7.0.5 in its CPDB workflow.

    00000106
    4.1K followersView on X

Explore more