CVE-2026-93769EPSS p18.9%
CVE-2026-93769CVE-2026-93769
Description
HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field Category title.
Scoring
| EPSS | 0.28% probability of exploitation · percentile 18.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-23 |