CVE-2026-29052

The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cross-Site Scripting (XSS) vulnerability in the Event Types of the HumHub Calendar module impacts users viewing events created by an administrative account. This issue has been patched in version 1.8.11.
Configurations

Configuration 1 (hide)

cpe:2.3:a:humhub:calendar:*:*:*:*:*:*:*:*

History

09 Mar 2026, 18:40

Type Values Removed Values Added
First Time Humhub calendar
Humhub
Summary
  • (es) El módulo de Calendario para HumHub permite a los usuarios crear eventos únicos o recurrentes, gestionar invitaciones de asistentes y rastrear eficientemente todas las actividades programadas. Antes de la versión 1.8.11, una vulnerabilidad de cross-site scripting (XSS) almacenado en los Tipos de Evento del módulo de Calendario de HumHub impacta a los usuarios que ven eventos creados por una cuenta administrativa. Este problema ha sido parcheado en la versión 1.8.11.
References () https://github.com/humhub/calendar/releases/tag/v1.8.11 - () https://github.com/humhub/calendar/releases/tag/v1.8.11 - Product, Release Notes
References () https://github.com/humhub/calendar/security/advisories/GHSA-gqj3-pmp2-mrx8 - () https://github.com/humhub/calendar/security/advisories/GHSA-gqj3-pmp2-mrx8 - Mitigation, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:humhub:calendar:*:*:*:*:*:*:*:*

05 Mar 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 06:16

Updated : 2026-03-09 18:40


NVD link : CVE-2026-29052

Mitre link : CVE-2026-29052

CVE.ORG link : CVE-2026-29052


JSON object : View

Products Affected

humhub

  • calendar
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')