CVE-2026-29052: HumHub Calendar Module: Stored XSS in Event Types
The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cross-Site Scripting (XSS) vulnerability in the Event Types of the HumHub Calendar module impacts users viewing events created by an administrative account. This issue has been patched in version 1.8.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29052?
CVE-2026-29052 has a moderate severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2026-29052?
To fix CVE-2026-29052, upgrade the HumHub Calendar Module to version 1.8.11 or later.
What versions of HumHub Calendar Module are affected by CVE-2026-29052?
CVE-2026-29052 affects all versions of the HumHub Calendar Module prior to version 1.8.11.
Is CVE-2026-29052 a critical vulnerability?
CVE-2026-29052 is not classified as critical but poses a significant risk of XSS exploitation.
What functionalities are impacted by CVE-2026-29052?
CVE-2026-29052 affects the creation and management of events, including invitations in the HumHub Calendar Module.