Horilla is a human resources management platform whose vulnerability profile concentrates in its core HR application and reflects the characteristic risks of web-based enterprise software handling sensitive employee data. The exposure recurs through application-layer weakness classes including cross-site scripting, improper access control, unrestricted file uploads, open redirects, and untrusted deserialization, each of which can enable credential theft, lateral movement, or data exfiltration in an HR context where defenders may have limited visibility into user behavior. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Horilla over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48868HIGH Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use | Sep 24, 2025 | 7.2 | 37 | NO | YES |
CVE-2025-59832CRITICAL Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket comment editor. A low-privilege | Sep 25, 2025 | 9.9 | 31 | NO | NO |
CVE-2026-24038HIGH Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that can be bypassed. When an OTP ex | Jan 22, 2026 | 8.1 | 30 | NO | NO |
CVE-2026-24010HIGH Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authenti | Jan 22, 2026 | 8.0 | 29 | NO | NO |
CVE-2025-48869HIGH Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predictin | Sep 24, 2025 | 7.5 | 24 | NO | NO |
CVE-2026-24037MEDIUM Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function attempts to block XSS by matching input against a set of regex p | Jan 22, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-24036MEDIUM Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recruitment/recruitment-details// e | Jan 22, 2026 | 5.3 | 23 | NO | NO |
CVE-2026-24034MEDIUM Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension a | Jan 22, 2026 | 5.4 | 23 | NO | NO |
CVE-2024-12138HIGH A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_curr | Dec 4, 2024 | 8.8 | 23 | NO | NO |
CVE-2026-3049MEDIUM A vulnerability was detected in horilla-opensource horilla up to 1.0.2. This issue affects the function get of the file horilla_generics/global_search.py of the component Query Par | Feb 24, 2026 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Horilla.
Media articles that mention a CVE ID that affects a product developed by Horilla — matched by CVE ID, not by vendor name.