ReviewHigh
CVE-2026-18526
HumHub
HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.
- CVSS
- 7.4
- EPSS
- 0.34% 26.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.20