VYPR
Vendor

Horilla Opensource

Products
3
CVEs
26
Across products
28
Status
Private

Products

3

Recent CVEs

26
View all 26 CVEs →
  • CVE-2025-59832CriSep 25, 2025
    risk 0.64cvss 9.9epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket comment editor. A low-privilege authenticated user could run arbitrary JavaScript in an admin’s browser, exfiltrate the…

  • CVE-2026-40866HigApr 21, 2026
    risk 0.56cvss —epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upload endpoint allows any authenticated user to overwrite or replace or corrupt another employee’s document by changing the…

  • CVE-2026-24038HigJan 22, 2026
    risk 0.53cvss 8.1epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that can be bypassed. When an OTP expires, the server returns None, and if an attacker omits the otp field from their POST request, the…

  • CVE-2026-24010HigJan 22, 2026
    risk 0.52cvss 8.0epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authenticated users to deploy phishing attacks. By uploading a malicious HTML file disguised as a profile…

  • CVE-2026-96795HigSep 25, 2026
    risk 0.50cvss 8.8epss 0.00

    Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated…

  • CVE-2025-48868HigSep 24, 2025
    risk 0.50cvss 7.2epss 0.02

    Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query parameter in the project_bulk_archive…

  • CVE-2025-48869HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predicting file URLs. These files are stored in a publicly accessible directory, allowing attackers to…

  • CVE-2026-71483HigSep 25, 2026
    risk 0.48cvss —epss 0.00

    Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript…

  • CVE-2026-40867HigApr 21, 2026
    risk 0.46cvss —epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing the attachment ID. This can expose…

  • CVE-2026-40865HigApr 21, 2026
    risk 0.46cvss —epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employees’ uploaded documents by changing the document ID in the request. This…

  • CVE-2024-12138MedDec 4, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_current_value_update/create_meetings/create_skills. The manipulation leads to deserialization. The…

  • CVE-2025-59525MedSep 24, 2025
    risk 0.40cvss 6.1epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed ), which can be chained to execute JavaScript whenever users view impacted content…

  • CVE-2025-59524MedSep 24, 2025
    risk 0.40cvss 6.1epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow performs validation only in the browser and does not enforce server-side checks. An attacker can bypass the client-side validation (for example, with an…

  • CVE-2026-63432MedSep 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a user-controlled body at /recruitment/get-mail-preview/ and /employee/get-employee-mail-preview with…

  • CVE-2026-63431MedSep 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_allowance, and view_single_deduction before loading records selected by emp_id, allowance_id, or…

  • CVE-2026-24034MedJan 22, 2026
    risk 0.35cvss 5.4epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. Version 1.5.0 fixes the issue.

  • CVE-2026-86066MedSep 25, 2026
    risk 0.31cvss —epss 0.00

    Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-request state through an HTTP GET before…

  • CVE-2026-24037MedJan 22, 2026
    risk 0.31cvss 4.8epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function attempts to block XSS by matching input against a set of regex patterns. However, the regexes are incomplete and context-agnostic, making them easy to bypass.…

  • CVE-2025-48867MedSep 24, 2025
    risk 0.31cvss 4.8epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerability in Horilla HRM 1.3.0 allows authenticated admin or privileged users to inject malicious JavaScript payloads into multiple fields in the Project and Task…

  • CVE-2026-24039MedJan 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, allowing low-privileged employees to self-approve documents they have uploaded. The document-approval UI is intended to be restricted to administrator or…