VulnSea

horilla-hr vulnerabilities

CVEs whose affected-version data names the horilla-hr package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-96795High· 8.8
yesterday

Horilla is an HR and CRM software

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Pyt…

▾ Twilighthorilla · horilla-hrvia NVD
CVE-2026-86066Medium· 5.9
yesterday

Horilla is an HR and CRM software

Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-reque…

▾ Sunlithorilla · horilla-hrvia NVD
CVE-2026-71483High· 8.5
yesterday

Horilla is an HR and CRM software

Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft …

▾ Twilighthorilla · horilla-hrvia NVD
CVE-2026-63432Medium· 6.5
yesterday

Horilla is an HR and CRM software

Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a user-controlled body at /recruitment/get-mail-preview/ and /…

▾ Sunlithorilla · horilla-hrvia NVD
CVE-2026-63431Medium· 6.5
yesterday

Horilla is an HR and CRM software

Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_allowance, and view_single_deduction before loading records sel…

▾ Sunlithorilla · horilla-hrvia NVD
horilla-hr vulnerabilities (CVEs) · VulnSea