---
id: CVE-2026-71483
title: Horilla is an HR and CRM software
summary: >-
  Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at
  /employee/employee-filter-view is reflected by jQuery .html() in
  employee/templates/employee_nav.html without HTML neutralization. An external
  attacker can craft …
severity: high
cvss: 8.5
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-79
vendor: horilla
product: horilla-hr
affected:
  - horilla-hr < 1.6.0
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T22:18:20.173'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71483'
references:
  - url: >-
      https://github.com/horilla/horilla-hr/commit/39ed01306341a1f6b7702df2825ab5431b5401a9
    label: security-advisories@github.com
  - url: >-
      https://github.com/horilla/horilla-hr/security/advisories/GHSA-rw86-x8hq-xgwh
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-25T22:20:31.563Z'
---

## Overview

Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript to execute when an authenticated employee or administrator reaches the employee filter, allowing access to browser-visible session data and actions with the victim's application privileges. This issue is fixed in version 1.6.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
