Stored Cross-Site Scripting Vulnerability in HumHub by HumHub Team
CVE-2026-18430

7.2HIGH

Key Information:

Vendor

Humhub

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-18430?

HumHub 1.18.4 is affected by a stored cross-site scripting vulnerability that allows an attacker to inject malicious HTML or JavaScript through the comment-deletion notification feature. When a space administrator deletes a user's comment, they can opt to notify the original author and include a crafted deletion reason that contains harmful scripts. This vulnerability could lead to exploitation by delivering malware or stealing sensitive information from unsuspecting users who interact with the compromised notifications.

Affected Version(s)

HumHub Windows 1.18.4

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel Gomez
Fluid Attacks' AI SAST Scanner
.