CVE-2026-96795 is a high-severity vulnerability in Horilla HR and CRM software prior to version 2.0.0. The vulnerability allows for arbitrary operating-system command execution with application process privileges by injecting Python syntax into a dynamic function definition. This issue is fixed in version 2.0.0. Defenders should assess exposure, review system configurations, monitor for potential exploita [truncated]
CVE-2026-71483 is a high-severity vulnerability in Horilla HR and CRM software prior to version 1.6.0. The issue allows an external attacker to craft a link that, when accessed by an authenticated employee or administrator, can execute JavaScript and access browser-visible session data and application actions with the victim's privileges. This vulnerability is fixed in version 1.6.0.