{"cve":"CVE-2026-93769","enrichment":{"created":"2026-09-23T18:00:07.947510+00:00","updated":"2026-09-23T18:00:07.947515+00:00","vendors":[]},"mitre":{"cpes":["cpe:2.3:a:humhub:humhub:1.18.5:*:linux:*:*:*:*:*","cpe:2.3:a:humhub:humhub:1.18.5:*:macos:*:*:*:*:*","cpe:2.3:a:humhub:humhub:1.18.5:*:windows:*:*:*:*:*"],"created":"2026-09-23T15:49:51.290000+00:00","description":"HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field Category title.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":7.2,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N"}},"mitre_repo_path":"cves/2026/93xxx/CVE-2026-93769.json","references":["https://fluidattacks.com/advisories/cali","https://github.com/humhub/humhub","https://github.com/humhub/humhub/pull/8499"],"title":"HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover","updated":"2026-09-23T16:40:14.392000+00:00","vendors":["humhub","humhub$PRODUCT$humhub"],"weaknesses":["CWE-79"]},"nvd":{"cpes":[],"created":"2026-09-23T16:16:48.360000+00:00","description":"HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field Category title.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":7.2,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-93769.json","references":["https://fluidattacks.com/advisories/cali","https://github.com/humhub/humhub","https://github.com/humhub/humhub/pull/8499"],"title":null,"updated":"2026-09-23T17:17:20.143000+00:00","vendors":[],"weaknesses":["CWE-79"]},"opencve":{"changes":[{"created":"2026-09-23T16:00:00+00:00","data":[{"details":{"new":"HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field Category title.","old":null},"type":"description"},{"details":{"new":"HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover","old":null},"type":"title"},{"details":["humhub","humhub$PRODUCT$humhub"],"type":"first_time"},{"details":{"added":["CWE-79"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:2.3:a:humhub:humhub:1.18.5:*:linux:*:*:*:*:*","cpe:2.3:a:humhub:humhub:1.18.5:*:macos:*:*:*:*:*","cpe:2.3:a:humhub:humhub:1.18.5:*:windows:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["humhub","humhub$PRODUCT$humhub"],"removed":[]},"type":"vendors"},{"details":{"added":["https://fluidattacks.com/advisories/cali","https://github.com/humhub/humhub","https://github.com/humhub/humhub/pull/8499"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":7.2,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"f806c317-769a-46fb-8907-7054b73b612f"},{"created":"2026-09-23T17:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"19315aec-ad72-49c0-b012-34b691a7d4a7"}],"cpes":{"data":["cpe:2.3:a:humhub:humhub:1.18.5:*:linux:*:*:*:*:*","cpe:2.3:a:humhub:humhub:1.18.5:*:macos:*:*:*:*:*","cpe:2.3:a:humhub:humhub:1.18.5:*:windows:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2026-09-23T15:49:51.290000+00:00","provider":"mitre"},"description":{"data":"HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field Category title.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{"score":7.2,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N"},"provider":"mitre"},"epss":{"data":{},"provider":null},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://fluidattacks.com/advisories/cali","https://github.com/humhub/humhub","https://github.com/humhub/humhub/pull/8499"],"providers":["mitre","nvd"]},"title":{"data":"HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover","provider":"mitre"},"updated":{"data":"2026-09-23T17:17:20.143000+00:00","provider":"nvd"},"vendors":{"data":["humhub","humhub$PRODUCT$humhub"],"providers":["mitre"]},"weaknesses":{"data":["CWE-79"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-09-23T15:49:51.290000+00:00","description":"HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field Category title.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover","updated":"2026-09-23T16:40:02.618000+00:00","vendors":[],"vulnrichment_repo_path":"2026/93xxx/CVE-2026-93769.json","weaknesses":[]}}