Cross-Site Scripting in Horilla HR and CRM Software
CVE-2026-71483

8.5HIGH

Key Information:

Vendor

Horilla

Vendor
CVE Published:
25 September 2026

What is CVE-2026-71483?

Horilla HR and CRM software, in versions before 1.6.0, contains a Cross-Site Scripting (XSS) vulnerability that allows external attackers to exploit the search parameter at /employee/employee-filter-view. This flaw arises due to the lack of HTML neutralization when using jQuery .html() in employee/templates/employee_nav.html. By delivering a crafted link, an attacker can execute malicious JavaScript upon an authenticated user accessing the employee filter, potentially exposing browser-visible session data and enabling unauthorized actions with the victim's application privileges. The issue has been resolved in version 1.6.0.

Affected Version(s)

horilla-hr < 1.6.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.