NONE · 0

CVE-2026-18526

HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.

Vulnerability Description

HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-18526?

CVE-2026-18526 is a documented vulnerability. HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.

How severe is CVE-2026-18526?

CVSS scoring is not yet available for CVE-2026-18526. Check NVD for updates.

Is there a patch for CVE-2026-18526?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.