Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion reason. | |
| Title | HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason | |
| First Time appeared |
Humhub
Humhub humhub |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:humhub:humhub:1.18.4:*:linux:*:*:*:*:* cpe:2.3:a:humhub:humhub:1.18.4:*:macos:*:*:*:*:* cpe:2.3:a:humhub:humhub:1.18.4:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Humhub
Humhub humhub |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-08-19T15:52:49.273Z
Reserved: 2026-07-30T19:14:38.414Z
Link: CVE-2026-18430
No data.
Status : Received
Published: 2026-08-19T16:17:06.463
Modified: 2026-08-19T16:17:06.463
Link: CVE-2026-18430
No data.
OpenCVE Enrichment
Updated: 2026-08-19T18:15:03Z