CVE-2026-29048: HumHub: XSS in Button component
HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0. Due to inconsistent output encoding at several points within the software, malicious scripts could be injected and executed in the context of the user's browser. This issue has been patched in version 1.18.1.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29048?
CVE-2026-29048 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2026-29048?
To fix CVE-2026-29048, update to HumHub version 1.19.0 or later, which addresses the inconsistent output encoding.
What software versions are affected by CVE-2026-29048?
CVE-2026-29048 specifically affects HumHub version 1.18.0.
What type of vulnerability is CVE-2026-29048?
CVE-2026-29048 is a cross-site scripting (XSS) vulnerability found in the Button component of HumHub.
Can CVE-2026-29048 be exploited by an attacker?
Yes, an attacker can potentially exploit CVE-2026-29048 to execute malicious scripts through the affected Button component.