📦 Horilla

by Horilla

🔍 What is Horilla?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-59832

CRITICAL CVSS 9.9 Sep 25, 2025

A stored cross-site scripting (XSS) vulnerability in Horilla HRMS allows low-privilege authenticated users to inject malicious JavaScript into ticket comments. When administrators view these comments,...

CVE-2026-24038

HIGH CVSS 8.1 Jan 22, 2026

This vulnerability allows attackers to bypass two-factor authentication in Horilla HRMS by omitting the OTP field from authentication requests. When the OTP expires, the server returns None, and if th...

CVE-2026-24010

HIGH CVSS 8.0 Jan 22, 2026

Horilla HRMS versions before 1.5.0 contain a critical file upload vulnerability that allows authenticated users to upload malicious HTML files disguised as profile pictures. This enables phishing atta...

CVE-2025-48868

HIGH CVSS 7.2 Sep 24, 2025

Horilla HRMS version 1.3.0 contains an authenticated Remote Code Execution vulnerability where privileged users (like administrators) can execute arbitrary system commands on the server. The vulnerabi...

CVE-2026-24039

MEDIUM CVSS 4.3 Jan 22, 2026

CVE-2026-24039 is an improper access control vulnerability in Horilla HRMS version 1.4.0 that allows low-privileged employees to self-approve documents they uploaded. This undermines HR process integr...

CVE-2026-24034

MEDIUM CVSS 5.4 Jan 22, 2026

Horilla HRMS versions before 1.5.0 contain a cross-site scripting vulnerability in the profile photo upload functionality. Attackers can upload malicious files that execute JavaScript in victims' brow...

CVE-2026-24035

MEDIUM CVSS 4.3 Jan 22, 2026

This vulnerability allows any authenticated employee in Horilla HRMS to upload documents on behalf of any other employee without proper authorization. It affects organizations using Horilla HR Softwar...

CVE-2026-24036

MEDIUM CVSS 5.3 Jan 22, 2026

This vulnerability in Horilla HRMS allows unauthenticated attackers to view unpublished job postings through an exposed API endpoint. Organizations using Horilla versions 1.4.0 and above are affected,...

CVE-2026-24037

MEDIUM CVSS 4.8 Jan 22, 2026

This CVE describes an XSS vulnerability in Horilla HRMS version 1.4.0 where incomplete regex patterns in the has_xss() function allow attackers to bypass XSS protection. Attackers can redirect users t...

CVE-2025-47789

MEDIUM CVSS 6.1 May 15, 2025

This is an open redirect vulnerability in Horilla HRMS that allows attackers to craft URLs that redirect users to external malicious domains after login. Attackers can use this to create convincing ph...

CVE-2024-12138

MEDIUM CVSS 6.3 Dec 4, 2024

A critical deserialization vulnerability in horilla up to version 1.2.1 allows remote attackers to execute arbitrary code by manipulating specific functions. This affects all systems running vulnerabl...

CVE-2026-3050

LOW CVSS 3.5 Feb 24, 2026

This CVE describes a cross-site scripting (XSS) vulnerability in Horilla CRM's Leads Module. Attackers can inject malicious scripts via the Notes argument in the global.js file, potentially compromisi...