CVE-2025-64442: Humhub

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search previews. This issue is fixed in version 1.17.4.

Affected products

  • Humhub Humhub: before 1.17.4 (fixed in 1.17.4)

Published 2025-11-07. Last modified 2026-06-17.