hubzero-cms

2 known vulnerabilities in hubzero-cms, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-92984 CVSS 8.5 high HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing…
  • CVE-2026-92970 CVSS 8.7 high HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project…