πŸ” CVE Alert

CVE-2026-93769

UNKNOWN 0.0

HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field Category title.

CWE CWE-79
Vendor humhub
Product humhub
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for humhub humhub

Be the first to know when new unknown vulnerabilities affecting humhub humhub are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

Humhub / Humhub
1.18.5

References

NVD β†— CVE.org β†— EPSS Data β†—
fluidattacks.com: https://fluidattacks.com/advisories/cali github.com: https://github.com/humhub/humhub github.com: https://github.com/humhub/humhub/pull/8499

Credits

Miguel GΓ³mez Fluid Attacks' AI SAST Scanner