{"id":"CVE-2026-18430","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-18430","summary":"HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify…","details":"HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion reason.","published":"2026-08-19T16:17:06.463","modified":"2026-08-19T16:17:06.463","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/humhub/humhub/pull/8365","label":"humhub/humhub#8365"},"references":[{"type":"WEB","url":"https://fluidattacks.com/es/advisories/personajes"},{"type":"WEB","url":"https://github.com/humhub/humhub"},{"type":"WEB","url":"https://github.com/humhub/humhub/pull/8365"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T16:17:06.463"}}