VYPR

Horilla

by Horilla Opensource

Source repositories

CVEs (17)

  • CVE-2025-59832CriSep 25, 2025
    risk 0.64cvss 9.9epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket comment editor. A low-privilege authenticated user could run arbitrary JavaScript in an admin’s browser, exfiltrate the…

  • CVE-2026-24038HigJan 22, 2026
    risk 0.53cvss 8.1epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that can be bypassed. When an OTP expires, the server returns None, and if an attacker omits the otp field from their POST request, the…

  • CVE-2026-24010HigJan 22, 2026
    risk 0.52cvss 8.0epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authenticated users to deploy phishing attacks. By uploading a malicious HTML file disguised as a profile…

  • CVE-2025-48869HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predicting file URLs. These files are stored in a publicly accessible directory, allowing attackers to…

  • CVE-2024-12138MedDec 4, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_current_value_update/create_meetings/create_skills. The manipulation leads to deserialization. The…

  • CVE-2025-59525MedSep 24, 2025
    risk 0.40cvss 6.1epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed ), which can be chained to execute JavaScript whenever users view impacted content…

  • CVE-2025-59524MedSep 24, 2025
    risk 0.40cvss 6.1epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow performs validation only in the browser and does not enforce server-side checks. An attacker can bypass the client-side validation (for example, with an…

  • CVE-2026-24034MedJan 22, 2026
    risk 0.35cvss 5.4epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. Version 1.5.0 fixes the issue.

  • CVE-2026-24037MedJan 22, 2026
    risk 0.31cvss 4.8epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function attempts to block XSS by matching input against a set of regex patterns. However, the regexes are incomplete and context-agnostic, making them easy to bypass.…

  • CVE-2025-48867MedSep 24, 2025
    risk 0.31cvss 4.8epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerability in Horilla HRM 1.3.0 allows authenticated admin or privileged users to inject malicious JavaScript payloads into multiple fields in the Project and Task…

  • CVE-2026-24039MedJan 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, allowing low-privileged employees to self-approve documents they have uploaded. The document-approval UI is intended to be restricted to administrator or…

  • CVE-2026-24035MedJan 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exists in Horilla HR Software starting in version 1.4.0 and prior to version 1.5.0, allowing any authenticated employee to upload documents on behalf of another…

  • CVE-2026-3050LowFeb 24, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in horilla-opensource horilla up to 1.0.2. Impacted is an unknown function of the file static/assets/js/global.js of the component Leads Module. This manipulation of the argument Notes causes cross site scripting. The attack is possible to be carried out…

  • CVE-2026-3049MedFeb 24, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in horilla-opensource horilla up to 1.0.2. This issue affects the function get of the file horilla_generics/global_search.py of the component Query Parameter Handler. The manipulation of the argument prev_url results in open redirect. The attack can…

  • CVE-2025-48868HigSep 24, 2025
    risk 0.03cvss 7.2epss 0.02

    Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query parameter in the project_bulk_archive…

  • CVE-2026-24036MedJan 22, 2026
    risk 0.00cvss 5.3epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recruitment/recruitment-details// endpoint without authentication. The response includes draft job titles, descriptions and…

  • CVE-2025-47789MedMay 15, 2025
    risk 0.00cvss 6.1epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attacker can craft a Horilla URL that refers to an external domain. Upon clicking and logging in, the user is redirected to an external domain. This allows the…