Cross-Site Scripting in HumHub Button Component
CVE-2026-29048
6.9MEDIUM
What is CVE-2026-29048?
In version 1.18.0 of HumHub, a cross-site scripting vulnerability was found in the Button component due to inconsistent output encoding. This flaw allows attackers to inject malicious scripts that can be executed in users' browsers, compromising their security. The issue has been addressed in version 1.18.1, and users are encouraged to update their installations to mitigate potential risks.
Affected Version(s)
humhub = 1.18.0
