CVE-2025-64442

Severity CVSS v4.0:
HIGH
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
07/11/2025
Last modified:
26/11/2025

Description

HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search previews. This issue is fixed in version 1.17.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:humhub:humhub:*:*:*:*:*:*:*:* 1.17.4 (excluding)