Stored Cross-Site Scripting Vulnerability in HumHub Community Edition by HumHub
CVE-2026-18526

7.4HIGH

Key Information:

Vendor

Humhub

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-18526?

HumHub Community Edition versions 1.18.4 and 1.18.4-pl1 are susceptible to a stored Cross-Site Scripting (XSS) vulnerability. This issue arises during the oEmbed confirmation rendering workflow, potentially allowing malicious users to inject arbitrary scripts. This could lead to unauthorized actions being performed on behalf of an authenticated user or the execution of harmful data within the client’s browser.

Affected Version(s)

HumHub Windows 1.18.4

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel Gomez
Fluid Attacks' AI SAST Scanner
.