{"id":"CVE-2026-71483","summary":"Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View","details":"Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript to execute when an authenticated employee or administrator reaches the employee filter, allowing access to browser-visible session data and actions with the victim's application privileges. This issue is fixed in version 1.6.0.","aliases":["GHSA-rw86-x8hq-xgwh"],"modified":"2026-09-27T03:47:28.168784323Z","published":"2026-09-25T21:59:50.220Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71483.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71483.json"},{"type":"ADVISORY","url":"https://github.com/horilla/horilla-hr/security/advisories/GHSA-rw86-x8hq-xgwh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71483"},{"type":"FIX","url":"https://github.com/horilla/horilla-hr/commit/39ed01306341a1f6b7702df2825ab5431b5401a9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/horilla/horilla-hr","events":[{"introduced":"0"},{"fixed":"39ed01306341a1f6b7702df2825ab5431b5401a9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.6.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.5.0","1.4.0","1.3.2","1.3.1","1.3","1.2.3","1.2.2","1.2.1","1.2.0","1.1.0","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71483.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}