HumHub is a modestly represented social collaboration and team communication platform that, despite a narrow product footprint, sits in the content-management and web-application tier where it handles user-generated content and sensitive organizational data. Its vulnerability disclosures cluster around web-application input handling and information exposure, with recurring weakness classes including cross-site scripting, SQL injection, and sensitive-data leakage that are characteristic of platforms managing user interaction and authentication. Vulnerabilities affecting this vendor frequently acquire public exploit code, and a meaningful share reach serious severity; defenders should track this vendor's updates for internet-reachable instances and prioritize patching. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Humhub over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-20028CRITICAL A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown part. The manipulation leads to privilege escalation. It is pos | Jun 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-11564MEDIUM A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/dat | May 8, 2019 | 6.1 | 30 | NO | YES |
CVE-2014-9528HIGH SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authen | Jan 6, 2015 | 7.5 | 28 | NO | YES |
CVE-2021-43847MEDIUM HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of pri | Dec 20, 2021 | 6.5 | 23 | NO | NO |
CVE-2026-29048MEDIUM HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0. Due to inconsi | Mar 6, 2026 | 6.1 | 22 | NO | NO |
CVE-2025-54790MEDIUM Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploitation of backend SQL queries wit | Aug 2, 2025 | 6.5 | 22 | NO | NO |
CVE-2017-20027MEDIUM A vulnerability was found in HumHub up to 1.0.1 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting | Jun 9, 2022 | 6.1 | 22 | NO | NO |
CVE-2017-20026MEDIUM A vulnerability has been found in HumHub up to 1.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site | Jun 9, 2022 | 6.1 | 22 | NO | NO |
CVE-2026-29052MEDIUM The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1 | Mar 5, 2026 | 6.1 | 21 | NO | NO |
CVE-2025-64442MEDIUM HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search | Nov 7, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Humhub.
Media articles that mention a CVE ID that affects a product developed by Humhub — matched by CVE ID, not by vendor name.