VYPR

Horilla Hr

by Horilla Opensource

Source repositories

CVEs (9)

  • CVE-2026-40866HigApr 21, 2026
    risk 0.56cvss —epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upload endpoint allows any authenticated user to overwrite or replace or corrupt another employee’s document by changing the…

  • CVE-2026-96795HigSep 25, 2026
    risk 0.50cvss 8.8epss 0.00

    Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated…

  • CVE-2026-71483HigSep 25, 2026
    risk 0.48cvss —epss 0.00

    Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript…

  • CVE-2026-40867HigApr 21, 2026
    risk 0.46cvss —epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing the attachment ID. This can expose…

  • CVE-2026-40865HigApr 21, 2026
    risk 0.46cvss —epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employees’ uploaded documents by changing the document ID in the request. This…

  • CVE-2026-63432MedSep 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a user-controlled body at /recruitment/get-mail-preview/ and /employee/get-employee-mail-preview with…

  • CVE-2026-63431MedSep 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_allowance, and view_single_deduction before loading records selected by emp_id, allowance_id, or…

  • CVE-2026-86066MedSep 25, 2026
    risk 0.31cvss —epss 0.00

    Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-request state through an HTTP GET before…

  • CVE-2026-41513MedMay 12, 2026
    risk 0.24cvss —epss 0.00

    Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirect users to arbitrary external URLs. This allows an attacker to turn trusted application links into phishing or social-engineering redirects.