Home

Description

HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search previews. This issue is fixed in version 1.17.4.

PUBLISHED Reserved 2025-11-03 | Published 2025-11-07 | Updated 2025-11-07 | Assigner GitHub_M




HIGH: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 1.17.4
affected

References

github.com/...humhub/security/advisories/GHSA-2hgp-33j2-93cc

github.com/humhub/humhub/pull/7814

github.com/humhub/humhub/releases/tag/v1.17.4

cve.org (CVE-2025-64442)

nvd.nist.gov (CVE-2025-64442)

Download JSON