CVE-2026-29048
HumHub: XSS in Button component
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0. Due to inconsistent output encoding at several points within the software, malicious scripts could be injected and executed in the context of the user's browser. This issue has been patched in version 1.18.1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
humhub · humhubWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →