CVE-2026-14192: Stored XSS in Bilin Software's HUMANIST Digital Human Resources
Published Aug 4, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Affected Software
1 affected component
Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources>=26.0<26.1
Event History
Aug 4, 2026
CVE Published
via MITRE·08:48 AM
Data Sourced
via MITRE·08:48 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14192?
CVE-2026-14192 has a medium severity score of 5.4.
2
What type of vulnerability is CVE-2026-14192?
CVE-2026-14192 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
3
How do I fix CVE-2026-14192?
To remediate CVE-2026-14192, upgrade to HUMANIST Digital Human Resources version 26.1 or above.
4
What software is affected by CVE-2026-14192?
CVE-2026-14192 affects versions of HUMANIST Digital Human Resources prior to 26.1.
5
What are the consequences of exploiting CVE-2026-14192?
Exploitation of CVE-2026-14192 can lead to unauthorized scripts being executed within the context of a user’s browser.