CVE-2026-29052
HumHub Calendar Module: Stored XSS in Event Types
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cross-Site Scripting (XSS) vulnerability in the Event Types of the HumHub Calendar module impacts users viewing events created by an administrative account. This issue has been patched in version 1.8.11.
| CWE | CWE-79 |
| Vendor | humhub |
| Product | calendar |
| Published | Mar 5, 2026 |
| Last Updated | Mar 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for humhub calendar
Be the first to know when new unknown vulnerabilities affecting humhub calendar are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
humhub / calendar
< 1.8.11