A vulnerability was found in LimeSurvey 7.0.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component HTML Editor Popup Endpoint. The manipulation of the argument text/name results in HTML injection.

This vulnerability is known as CVE-2026-63361. It is possible to launch the attack remotely. No exploit is available.