Known Vulnerabilities for Files by Humhub
Listed below are 2 of the newest known vulnerabilities associated with "Files" by "Humhub".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-108705 json | CordysCRM through 1.9.3 contains a missing authorization vulnerability in the POST /custom-form/data/import endpoint that all... | Not Provided | 2026-10-11 | 2026-10-11 |
| CVE-2026-108694 json | ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files be... | Not Provided | 2026-10-11 | 2026-10-11 |
| CVE-2026-108693 json | ImageMagick on Windows through 7.1.2-33 and 6.9.13-58 contains an uncontrolled search path vulnerability in NTGhostscriptEXE(... | Not Provided | 2026-10-11 | 2026-10-11 |
| CVE-2026-108688 json | Eladmin through 2.7 contains a missing authorization vulnerability in the LocalStorageController uploadPicture handler that a... | Not Provided | 2026-10-11 | 2026-10-11 |
| CVE-2026-108654 json | JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OssFileController queryById handler that allows... | Not Provided | 2026-10-10 | 2026-10-10 |
| CVE-2026-108603 json | slide-maker through 5.8.0 contains a path traversal vulnerability in generate_images_openai.py that allows attackers to write... | Not Provided | 2026-10-10 | 2026-10-10 |
| CVE-2026-108600 json | open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the file_write tool... | Not Provided | 2026-10-10 | 2026-10-10 |
| CVE-2026-108599 json | phi 0.1.1 through 0.28.4 contains an improper link resolution vulnerability that allows malicious repositories to bypass work... | Not Provided | 2026-10-10 | 2026-10-10 |
| CVE-2026-108597 json | Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in _s3_models_dir_to_tarfile that a... | Not Provided | 2026-10-10 | 2026-10-10 |
| CVE-2026-108591 json | InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create perm... | Not Provided | 2026-10-10 | 2026-10-10 |