You can report vulnerabilities privately to security@humhub.com. The HumHub team will triage the issue, and work with you on a coordinated disclosure timeline.
Security: humhub/humhub
Security
SECURITY.md
-
Privilege escalation through unvalidated Space member role changesGHSA-r99w-2h6v-g5m5 published
Aug 19, 2026 by kilgor-trout-c22High -
Missing authorization on the group add members actionGHSA-pvw6-x9ww-4rff published
Aug 19, 2026 by kilgor-trout-c22High -
Reflected cross-site scripting in the Space membership request buttonGHSA-7qgg-m37j-9fcj published
Aug 19, 2026 by kilgor-trout-c22High -
Stored cross-site scripting in the oEmbed consent promptGHSA-m5h7-8mm5-c39m published
Aug 19, 2026 by kilgor-trout-c22High -
Stored cross-site scripting in comment and content deletion notificationsGHSA-vc4p-rvj7-hhjg published
Aug 19, 2026 by kilgor-trout-c22High -
Missing Authorization on Remove All Space Members ActionGHSA-hj67-5q6h-j7c2 published
May 19, 2026 by kilgor-trout-c22Moderate -
XSS in Button componentGHSA-qxjh-478x-23gm published
Mar 2, 2026 by luke-Moderate -
XSS in Meta Search componentGHSA-2hgp-33j2-93cc published
Nov 5, 2025 by luke-High -
XSS in Space AdminGHSA-p7h3-73v7-959c published
Jul 6, 2022 by luke-High -
Improper access control when user is forced to change passwordGHSA-2h35-f226-3f57 published
Apr 19, 2022 by luke-Critical
Learn more about advisories related to humhub/humhub in the GitHub Advisory Database