VulnerabilityAnalyzed
CVE-2026-29048
In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0.
MEDIUM 6.9EPSS 0.19%
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0. Due to inconsistent output encoding at several points within the software, malicious scripts could be injected and executed in the context of the user's browser. This issue has been patched in version 1.18.1.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.19% probability · 9th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- humhub/humhub
- Source
- security-advisories@github.com
References
- https://github.com/humhub/humhub/commit/bd06ab4c75f6c65295ee3e1ce3643437e8f9d10aPatch
- https://github.com/humhub/humhub/pull/8039Issue Tracking, Patch
- https://github.com/humhub/humhub/releases/tag/v1.18.1Product, Release Notes
- https://github.com/humhub/humhub/security/advisories/GHSA-qxjh-478x-23gmVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.