The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cross-Site Scripting (XSS) vulnerability in the Event Types of the HumHub Calendar module impacts users viewing events created by an administrative account. This issue has been patched in version 1.8.11.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:humhub:calendar:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Humhub
Humhub calendar |
|
| Vendors & Products |
Humhub
Humhub calendar |
Thu, 05 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Mar 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cross-Site Scripting (XSS) vulnerability in the Event Types of the HumHub Calendar module impacts users viewing events created by an administrative account. This issue has been patched in version 1.8.11. | |
| Title | HumHub Calendar Module: Stored XSS in Event Types | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-05T05:48:10.557Z
Updated: 2026-03-05T15:30:11.121Z
Reserved: 2026-03-03T17:50:11.244Z
Link: CVE-2026-29052
Updated: 2026-03-05T15:30:07.662Z
Status : Analyzed
Published: 2026-03-05T06:16:50.260
Modified: 2026-03-09T18:40:51.523
Link: CVE-2026-29052
No data.