CVE-2026-93769
HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field Category title.
| CWE | CWE-79 |
| Vendor | humhub |
| Product | humhub |
| Published | Sep 23, 2026 |
| Last Updated | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for humhub humhub
Be the first to know when new unknown vulnerabilities affecting humhub humhub are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Humhub / Humhub
1.18.5
References
Credits
Miguel GΓ³mez Fluid Attacks' AI SAST Scanner