Skip to main content

Vendor archive

humhub CVEs

Beta · best-effort

18 CVEs tagged to vendor humhub1 Critical, 2 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2026-29048

Published Mar 6, 2026

HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0. Due to incons…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-29052

Published Mar 5, 2026

The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-64442

Published Nov 7, 2025

HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54790

Published Aug 2, 2025

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploitation of backend SQL queries wi…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-54789

Published Aug 2, 2025

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functionality does not contain logic that prevents injection of a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52043

Published Nov 6, 2024

Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released HumHub…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31133

Published Jul 7, 2022

HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, the attacker…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-20028

Published Jun 9, 2022

A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown part. The manipulation leads to privilege escalation. It is po…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-20027

Published Jun 9, 2022

A vulnerability was found in HumHub up to 1.0.1 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-20026

Published Jun 9, 2022

A vulnerability has been found in HumHub up to 1.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross sit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24865

Published Apr 20, 2022

HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This iss…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43847

Published Dec 20, 2021

HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of pr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12743

Published Jul 29, 2019

HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11564

Published May 8, 2019

A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/da…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9094

Published Mar 21, 2019

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in /s/adada/cfiles/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing JavaScript in…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9093

Published Mar 21, 2019

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in file/file/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing a JavaScript payload…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1229

Published Jun 5, 2016

Cross-site scripting (XSS) vulnerability in HumHub 0.20.0-beta.1 through 0.20.1 and 1.0.0-beta before 1.0.0-beta.3 allows remote authenticated users to inject arbitrary web script…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9528

Published Jan 6, 2015

SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1