📦

humhub

Vendor: humhub

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 0 Remote Access
Total CVEs 29 Total Indexed
Avg. EPSS 0.57% Exploit Prob.
Latest CVE CVE-2026-29048 Mar 06

Security Vulnerability Index

Page 2 / 3
6.1 CVSS

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in /s/adada/cfiles/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing JavaScript in the filename is echoed back in JavaScript code, which resulted in XSS.

EPSS: 0.24%
6.1 CVSS

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in file/file/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing a JavaScript payload in the filename parameter is echoed back, which resulted in reflected XSS.

EPSS: 0.24%
5.4 CVSS

Cross-site scripting (XSS) vulnerability in HumHub 0.20.0-beta.1 through 0.20.1 and 1.0.0-beta before 1.0.0-beta.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 0.22%
7.5 CVSS
CVE-2014-9528
Exploit Found

SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the from parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks via a request that causes an error.

EPSS: 3.24%