HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 19 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow. | |
| Title | HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation | |
| First Time appeared |
Humhub
Humhub humhub |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:humhub:humhub:1.18.4:*:linux:*:*:*:*:* cpe:2.3:a:humhub:humhub:1.18.4:*:macos:*:*:*:*:* cpe:2.3:a:humhub:humhub:1.18.4:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Humhub
Humhub humhub |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-08-19T14:17:00.896Z
Reserved: 2026-07-31T19:46:36.482Z
Link: CVE-2026-18526
No data.
Status : Received
Published: 2026-08-19T15:16:58.010
Modified: 2026-08-19T15:16:58.010
Link: CVE-2026-18526
No data.
OpenCVE Enrichment
Updated: 2026-08-19T17:45:03Z
Weaknesses