Horilla
6 exploits
Active since May 2025
Horilla: Open Redirect via Unvalidated `next` Parameter in Notification Endpoints
horilla-opensource horilla <=1.0.2 - Open Redirect
CVSS 4.3
horilla < 1.0.3 - Cross-Site Scripting via Leads Module Notes Parameter
CVSS 3.5
horilla <= 1.3 - Open Redirect via Crafted URL
CVSS 6.1
Horilla 1.3.0 - Authenticated Remote Code Execution via Eval Injection in project_bulk_archive
CVSS 7.2
Horilla 1.4.0-1.4.x - Unauthenticated Unpublished Job Posting Exposure via Recruitment Details Endpoint
CVSS 5.3