Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-54789

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functionality does not contain logic that prevents injection of arbitrary JavaScript, which can lead to Browser JS code execution in the context of the user’s session. This is fixed in version 0.16.10.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.1%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-54789
  • Humhub » Files » Version: Any
    cpe:2.3:a:humhub:files:*


Contact Us

Shodan ® - All rights reserved