๐Ÿ” CVE Alert

CVE-2026-29052

UNKNOWN 0.0

HumHub Calendar Module: Stored XSS in Event Types

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cross-Site Scripting (XSS) vulnerability in the Event Types of the HumHub Calendar module impacts users viewing events created by an administrative account. This issue has been patched in version 1.8.11.

CWE CWE-79
Vendor humhub
Product calendar
Published Mar 5, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for humhub calendar

Be the first to know when new unknown vulnerabilities affecting humhub calendar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

humhub / calendar
< 1.8.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/humhub/calendar/security/advisories/GHSA-gqj3-pmp2-mrx8 github.com: https://github.com/humhub/calendar/releases/tag/v1.8.11