CVE-2026-18430
- EPSS 0.37%
- Veröffentlicht 19.08.2026 15:52:49
- Zuletzt bearbeitet 19.08.2026 20:17:13
HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion rea...
CVE-2026-18756
- EPSS 0.34%
- Veröffentlicht 19.08.2026 14:46:25
- Zuletzt bearbeitet 21.08.2026 17:16:30
HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership...
CVE-2026-18526
- EPSS 0.34%
- Veröffentlicht 19.08.2026 14:17:00
- Zuletzt bearbeitet 21.08.2026 17:16:29
HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.
CVE-2026-47657
- EPSS 0.22%
- Veröffentlicht 21.07.2026 17:50:08
- Zuletzt bearbeitet 23.07.2026 16:04:11
HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regard...
CVE-2026-29048
- EPSS 0.19%
- Veröffentlicht 06.03.2026 07:16:01
- Zuletzt bearbeitet 09.03.2026 21:23:43
HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0. Due to inconsistent output encoding at several points within the software, malicious...
CVE-2025-64442
- EPSS 0.23%
- Veröffentlicht 07.11.2025 20:28:20
- Zuletzt bearbeitet 26.11.2025 15:41:54
HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search previews. This issue is fixed in version 1.17.4.
CVE-2024-52043
- EPSS 0.43%
- Veröffentlicht 06.11.2024 08:15:03
- Zuletzt bearbeitet 08.11.2024 20:39:36
Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released HumHub versions: through 1.16.2.
CVE-2022-31133
- EPSS 0.68%
- Veröffentlicht 07.07.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:03:58
HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, the attacker would need a permission to administer the Spaces feature. The names of...
CVE-2017-20028
- EPSS 0.79%
- Veröffentlicht 09.06.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 03:22:28
A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown part. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is a...
CVE-2017-20027
- EPSS 0.62%
- Veröffentlicht 09.06.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 03:22:28
A vulnerability was found in HumHub up to 1.0.1 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting (DOM). The attack may be launched remotely. The exploit has been discl...