A vulnerability described as critical has been identified in LimeSurvey up to 6.17.10/7.0.4. The impacted element is the function getTemplateData of the component REST API survey template endpoint. Executing a manipulation of the argument Host can lead to server-side request forgery.

This vulnerability appears as CVE-2026-63107. The attack may be performed from remote. There is no available exploit.