CVE-2025-64442: HumHub is vulnerable to XSS through its Meta Search component
Published Nov 7, 2025
·Updated
HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search previews. This issue is fixed in version 1.17.4.
Affected Software
2 affected components
Humhub Humhub<1.17.4
Humhub Humhub<1.17.4
Remediation
Patch Available
Event History
Nov 7, 2025
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64442?
CVE-2025-64442 is classified as a medium severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-64442?
To fix CVE-2025-64442, upgrade HumHub to version 1.17.4 or later.
3
What is the impact of CVE-2025-64442?
The impact of CVE-2025-64442 allows attackers to execute malicious scripts through the Meta-Search feature.
4
Which versions of HumHub are affected by CVE-2025-64442?
HumHub versions below 1.17.4 are affected by CVE-2025-64442.
5
Is there a patch for CVE-2025-64442?
Yes, the patch for CVE-2025-64442 is included in HumHub version 1.17.4.