Stored Cross-Site Scripting Vulnerability in HumHub Calendar Module
CVE-2026-29052

6.9MEDIUM

Key Information:

Vendor

Humhub

Status
Vendor
CVE Published:
5 March 2026

What is CVE-2026-29052?

The Calendar module in HumHub allows users to create and manage events, but prior to version 1.8.11, it was exposed to a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs when an attacker manages to embed malicious scripts within event details, potentially affecting users who view these events under an administrative account. As a result, users may inadvertently execute harmful scripts. The vulnerability has been addressed in version 1.8.11, emphasizing the importance of keeping applications up to date.

Affected Version(s)

calendar < 1.8.11

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.