Horilla-opensource
13 CVEs tracked since 2025. Since Sep 2025, none of them reached CISA KEV.
Horilla-opensource CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-09 | 6 | 0 |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | 7 | 0 |
Products
The products that kept showing up in Horilla-opensource's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Horilla-opensource.
- CVE-2026-40867Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation—
- CVE-2026-40866Horilla: Unauthorized Document Overwrite via File Upload Endpoint—
- CVE-2026-40865Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id>—
- CVE-2026-3050horilla-opensource horilla Leads global.js cross site scripting3.5
- CVE-2026-3049horilla-opensource horilla Query Parameter global_search.py get redirect4.3
- CVE-2026-24039Horilla's Improper Access Control Allows Employees to Auto-Approve Documents4.3
- CVE-2026-24038Horilla HR has 2FA Bypass through its OTP Handling Logic8.1
- CVE-2026-24037Horilla HRM has XSS Bypass through Project Name4.8
- CVE-2026-24036Horilla Exposes Unpublished Job Disclosures through Unauthenticated API5.3
- CVE-2026-24035Horilla has Improper Access Control Issue that Allows Unauthorized Document Upload on Behalf of Another Employee4.3
- CVE-2026-24034Horilla has File Upload XSS5.4
- CVE-2026-24010Horilla has HTML Injection Issue that, with Phishing, Leads to Account Takeover8.0
- CVE-2025-59832Horrila Stored XSS Vulnerability via Ticket Comment section9.9
- CVE-2025-59525Horilla has Improper Input Sanitization Leading to XSS and Admin Account Takeover6.1
- CVE-2025-59524Horilla Stored XSS Vulnerability via File Upload in Reimbursement Panel6.1
The record
- Peak rank
- #121 in Sep 2025
- Busiest month shown
- Jan 2026, 7 CVEs
- Months with a KEV entry
- 0 since Sep 2025
- Monthly snapshots
- 2 since 2025