Humhub

Humhub

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 06.03.2026 07:16:01
  • Zuletzt bearbeitet 06.03.2026 07:16:01

HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0. Due to inconsistent output encoding at several points within the software, malicious...

  • EPSS 0.04%
  • Veröffentlicht 07.11.2025 20:28:20
  • Zuletzt bearbeitet 26.11.2025 15:41:54

HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search previews. This issue is fixed in version 1.17.4.

  • EPSS 0.25%
  • Veröffentlicht 06.11.2024 08:15:03
  • Zuletzt bearbeitet 08.11.2024 20:39:36

Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released HumHub versions: through 1.16.2.

  • EPSS 0.3%
  • Veröffentlicht 07.07.2022 18:15:09
  • Zuletzt bearbeitet 21.11.2024 07:03:58

HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, the attacker would need a permission to administer the Spaces feature. The names of...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 09.06.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:28

A vulnerability has been found in HumHub up to 1.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting (Reflected). The attack can be launched remotely. The explo...

  • EPSS 0.33%
  • Veröffentlicht 09.06.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:28

A vulnerability was found in HumHub up to 1.0.1 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting (DOM). The attack may be launched remotely. The exploit has been discl...

  • EPSS 0.33%
  • Veröffentlicht 09.06.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 03:22:28

A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown part. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is a...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 20.04.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:16

HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the H...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 20.12.2021 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:55

HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.

Exploit
  • EPSS 1.72%
  • Veröffentlicht 08.05.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:21:21

A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index.php POST request.