Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

horilla-opensource — Vulnerabilities & Security Advisories 19

Browse all 19 CVE security advisories affecting horilla-opensource. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Horilla-opensource is an HR management platform designed for streamlining workforce operations and employee data handling. Historically, the project has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its 19 recorded CVEs. Security researchers have identified consistent weaknesses in access controls and input validation, with several critical RCE flaws allowing unauthorized system compromise. While no major public security incidents have been documented, the high concentration of CVEs suggests ongoing challenges in secure development practices, particularly in authentication mechanisms and data sanitization.

Top products by horilla-opensource: horilla
CVE ID Title CVSS Severity Published
CVE-2026-40867 Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation — horilla CWE-284 6.5AI Medium AI 2026-04-21
CVE-2026-40866 Horilla: Unauthorized Document Overwrite via File Upload Endpoint — horilla CWE-284 4.3AI Medium AI 2026-04-21
CVE-2026-40865 Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id> — horilla CWE-284 6.5AI Medium AI 2026-04-21
CVE-2026-3050 horilla-opensource horilla Leads global.js cross site scripting — horilla CWE-79 3.5 Low 2026-02-24
CVE-2026-3049 horilla-opensource horilla Query Parameter global_search.py get redirect — horilla CWE-601 4.3 Medium 2026-02-24
CVE-2026-24039 Horilla's Improper Access Control Allows Employees to Auto-Approve Documents — horilla CWE-284 4.3 Medium 2026-01-22
CVE-2026-24038 Horilla HR has 2FA Bypass through its OTP Handling Logic — horilla CWE-287 8.1 High 2026-01-22
CVE-2026-24037 Horilla HRM has XSS Bypass through Project Name — horilla CWE-79 4.8 Medium 2026-01-22
CVE-2026-24036 Horilla Exposes Unpublished Job Disclosures through Unauthenticated API — horilla CWE-284 5.3 Medium 2026-01-22
CVE-2026-24035 Horilla has Improper Access Control Issue that Allows Unauthorized Document Upload on Behalf of Another Employee — horilla CWE-284 4.3 Medium 2026-01-22
CVE-2026-24034 Horilla has File Upload XSS — horilla CWE-434 5.4 Medium 2026-01-22
CVE-2026-24010 Horilla has HTML Injection Issue that, with Phishing, Leads to Account Takeover — horilla CWE-74 8.0AI High AI 2026-01-22
CVE-2025-59832 Horrila Stored XSS Vulnerability via Ticket Comment section — horilla CWE-79 9.9 Critical 2025-09-25
CVE-2025-59525 Horilla has Improper Input Sanitization Leading to XSS and Admin Account Takeover — horilla CWE-79 5.4AI Medium AI 2025-09-24
CVE-2025-59524 Horilla Stored XSS Vulnerability via File Upload in Reimbursement Panel — horilla CWE-79 8.8AI High AI 2025-09-24
CVE-2025-48867 Horilla Stored Cross-Site Scripting (XSS) Vulnerability in Project and Task Modules — horilla CWE-79 4.8 Medium 2025-09-24
CVE-2025-48869 Horilla Unauthorized Access to Candidate Resume Files Due to Broken Access Control — horilla CWE-284 7.5 High 2025-09-24
CVE-2025-48868 Horilla vulnerable to authenticated RCE via eval() in project_bulk_archive — horilla CWE-95 7.2 High 2025-09-24
CVE-2025-47789 Horilla Open Redirect Vulnerability in Login — horilla CWE-601 6.1 Medium 2025-05-15

This page lists every published CVE security advisory associated with horilla-opensource. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.