Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Horilla

First CVE: Dec 4, 2024Active for: 2 yearsTotal CVEs: 17
40.6
VTI Score
High

Horilla is a human resources management platform whose vulnerability profile concentrates in its core HR application and reflects the characteristic risks of web-based enterprise software handling sensitive employee data. The exposure recurs through application-layer weakness classes including cross-site scripting, improper access control, unrestricted file uploads, open redirects, and untrusted deserialization, each of which can enable credential theft, lateral movement, or data exfiltration in an HR context where defenders may have limited visibility into user behavior. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
5.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Horilla over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 4, 2024
19 months ago
Most Recent CVE
Feb 24, 2026
150 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-48868HIGH
Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use
Sep 24, 20257.237NOYES
CVE-2025-59832CRITICAL
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket comment editor. A low-privilege
Sep 25, 20259.931NONO
CVE-2026-24038HIGH
Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that can be bypassed. When an OTP ex
Jan 22, 20268.130NONO
CVE-2026-24010HIGH
Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authenti
Jan 22, 20268.029NONO
CVE-2025-48869HIGH
Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predictin
Sep 24, 20257.524NONO
CVE-2026-24037MEDIUM
Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function attempts to block XSS by matching input against a set of regex p
Jan 22, 20265.423NONO
CVE-2026-24036MEDIUM
Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recruitment/recruitment-details// e
Jan 22, 20265.323NONO
CVE-2026-24034MEDIUM
Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension a
Jan 22, 20265.423NONO
CVE-2024-12138HIGH
A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_curr
Dec 4, 20248.823NONO
CVE-2026-3049MEDIUM
A vulnerability was detected in horilla-opensource horilla up to 1.0.2. This issue affects the function get of the file horilla_generics/global_search.py of the component Query Par
Feb 24, 20266.122NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
65%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (47.1%)
Unknown0 (0.0%)
Required9 (52.9%)
Privileges Required
Low9 (52.9%)
High2 (11.8%)
None6 (35.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Horilla.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Horilla — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Horilla's Products

View all 2 CNAs →

Top CWEs