Humanica's vulnerability footprint centers on its Humatrix platform, a human resources and workforce management system, with the durable signal rooted in access-control and authentication weaknesses such as authorization bypass through user-controlled keys, incorrect default permissions, missing authentication for critical functions, and use of insufficiently random values. These classes reflect typical risks in enterprise HR applications handling sensitive employee data and access decisions; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Humanica over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15130CRITICAL The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a craft | Aug 18, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-16106HIGH The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/ | Sep 10, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-14932HIGH The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website via a modified selApp variable to | Aug 12, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-15129MEDIUM The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by speci | Aug 18, 2019 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Humanica.
Media articles that mention a CVE ID that affects a product developed by Humanica — matched by CVE ID, not by vendor name.