CVE-2025-54789: Humhub Files
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functionality does not contain logic that prevents injection of arbitrary JavaScript, which can lead to Browser JS code execution in the context of the user’s session. This is fixed in version 0.16.10.
Affected products
- Humhub Files: before 0.16.10 (fixed in 0.16.10)
Published 2025-08-02. Last modified 2026-09-02.