CVE Tools

Humhub

19 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Humhub, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Humhub CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Humhub CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-020
2026-031
2026-040
2026-050
2026-060
2026-071
2026-083
2026-091

Severity

How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High18%
  • Medium1292%

Latest CVEs

The 15 most recently published vulnerabilities affecting Humhub.

  1. CVE-2026-93769HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover—
  2. CVE-2026-18430HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason—
  3. CVE-2026-18756HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering—
  4. CVE-2026-18526HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation—
  5. CVE-2026-47657HumHub Missing Authorization on Remove All Space Members Action—
  6. CVE-2026-29048HumHub: XSS in Button component—
  7. CVE-2025-64442HumHub is vulnerable to XSS through its Meta Search component6.1
  8. CVE-2024-52043User enumeration in HubHub5.3
  9. CVE-2022-31133Cross site scripting in HumHub5.9
  10. CVE-2017-20028HumHub privileges management5.6
  11. CVE-2017-20027HumHub DOM cross site scriting4.3
  12. CVE-2017-20026HumHub Reflected cross site scriting4.3
  13. CVE-2022-24865Improper access control in humhub6.5
  14. CVE-2021-43847Authorization Bypass in Space Invite in HumHub6.5
  15. CVE-2019-11564A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index....6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store