Humhub
19 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Humhub, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
Humhub CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 3 |
| 2026-09 | 1 |
Severity
How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High1
- Medium12
Latest CVEs
The 15 most recently published vulnerabilities affecting Humhub.
- CVE-2026-93769HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover—
- CVE-2026-18430HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason—
- CVE-2026-18756HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering—
- CVE-2026-18526HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation—
- CVE-2026-47657HumHub Missing Authorization on Remove All Space Members Action—
- CVE-2026-29048HumHub: XSS in Button component—
- CVE-2025-64442HumHub is vulnerable to XSS through its Meta Search component6.1
- CVE-2024-52043User enumeration in HubHub5.3
- CVE-2022-31133Cross site scripting in HumHub5.9
- CVE-2017-20028HumHub privileges management5.6
- CVE-2017-20027HumHub DOM cross site scriting4.3
- CVE-2017-20026HumHub Reflected cross site scriting4.3
- CVE-2022-24865Improper access control in humhub6.5
- CVE-2021-43847Authorization Bypass in Space Invite in HumHub6.5
- CVE-2019-11564A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index....6.1
Product grouping is registry-driven, with AI assist and human review. How it works