PatchSiren

Humhub CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH HumHub CVE published 2026-08-19

CVE-2026-18526

CVE-2026-18526 is a stored Cross-Site Scripting (XSS) vulnerability affecting HumHub Community Edition versions 1.18.4 and 1.18.4-pl1. The vulnerability impacts the oEmbed confirmation rendering workflow. Due to limited source detail, defenders should verify affected scope and severity through official advisories or CVE records. The CVE record was published on 2026-08-19T15:16:58.010Z and has not been mod [truncated]

MEDIUM Humhub CVE published 2026-03-05

CVE-2026-29052

The CVE-2026-29052 vulnerability is a Stored Cross-Site Scripting (XSS) issue in the Event Types of the HumHub Calendar module. This vulnerability impacts users viewing events created by an administrative account. The issue has been patched in version 1.8.11. Affected users should prioritize patching to prevent Stored Cross-Site Scripting (XSS) attacks. The CVE record was published on 2026-03-05T06:16:50. [truncated]