Stored Cross-Site Scripting Vulnerability in HumHub by HumHub Team
CVE-2026-18430
7.2HIGH
What is CVE-2026-18430?
HumHub 1.18.4 is affected by a stored cross-site scripting vulnerability that allows an attacker to inject malicious HTML or JavaScript through the comment-deletion notification feature. When a space administrator deletes a user's comment, they can opt to notify the original author and include a crafted deletion reason that contains harmful scripts. This vulnerability could lead to exploitation by delivering malware or stealing sensitive information from unsuspecting users who interact with the compromised notifications.
Affected Version(s)
HumHub Windows 1.18.4
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Miguel Gomez
Fluid Attacks' AI SAST Scanner
