Humhub

Humhub

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 23.09.2026 15:49:51
  • Zuletzt bearbeitet 23.09.2026 17:17:20

HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field...

  • EPSS 0.37%
  • Veröffentlicht 19.08.2026 15:52:49
  • Zuletzt bearbeitet 28.08.2026 15:31:31

HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion rea...

  • EPSS 0.34%
  • Veröffentlicht 19.08.2026 14:46:25
  • Zuletzt bearbeitet 28.08.2026 15:31:31

HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership...

  • EPSS 0.34%
  • Veröffentlicht 19.08.2026 14:17:00
  • Zuletzt bearbeitet 28.08.2026 15:31:31

HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.

  • EPSS 0.22%
  • Veröffentlicht 21.07.2026 17:50:08
  • Zuletzt bearbeitet 23.07.2026 16:04:11

HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regard...

  • EPSS 0.19%
  • Veröffentlicht 06.03.2026 07:16:01
  • Zuletzt bearbeitet 09.03.2026 21:23:43

HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0. Due to inconsistent output encoding at several points within the software, malicious...

  • EPSS 0.23%
  • Veröffentlicht 07.11.2025 20:28:20
  • Zuletzt bearbeitet 26.11.2025 15:41:54

HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search previews. This issue is fixed in version 1.17.4.

  • EPSS 0.43%
  • Veröffentlicht 06.11.2024 08:15:03
  • Zuletzt bearbeitet 08.11.2024 20:39:36

Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released HumHub versions: through 1.16.2.

  • EPSS 0.68%
  • Veröffentlicht 07.07.2022 18:15:09
  • Zuletzt bearbeitet 21.11.2024 07:03:58

HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, the attacker would need a permission to administer the Spaces feature. The names of...

  • EPSS 0.79%
  • Veröffentlicht 09.06.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:28

A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown part. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is a...