No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion reason. | |
| Title | HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason | |
| First Time appeared |
Humhub
Humhub humhub |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:humhub:humhub:1.18.4:*:linux:*:*:*:*:* cpe:2.3:a:humhub:humhub:1.18.4:*:macos:*:*:*:*:* cpe:2.3:a:humhub:humhub:1.18.4:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Humhub
Humhub humhub |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-08-19T19:21:03.424Z
Reserved: 2026-07-30T19:14:38.414Z
Link: CVE-2026-18430
Updated: 2026-08-19T19:20:54.892Z
Status : Received
Published: 2026-08-19T16:17:06.463
Modified: 2026-08-19T20:17:13.353
Link: CVE-2026-18430
No data.
OpenCVE Enrichment
Updated: 2026-08-19T18:15:03Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')