{"api_version":"v1","generated_at":"2026-10-08T05:40:00+00:00","product":{"cve_count":19,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-horilla-opensource-horilla-9c66bc705707","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"horilla","next_cursor":null,"observations":[{"affected":"1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-40867","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40867","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-21T20:36:38.138Z","patch_url":"","primary_source":"","published":"2026-04-21T18:16:29.345Z"},{"affected":"1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-40866","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40866","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-21T19:29:21.663Z","patch_url":"","primary_source":"","published":"2026-04-21T18:15:30.126Z"},{"affected":"1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-40865","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40865","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-21T18:45:50.143Z","patch_url":"","primary_source":"","published":"2026-04-21T18:14:19.523Z"},{"affected":"1.0.0; 1.0.1; 1.0.2","affected_versions_present":true,"cve_id":"CVE-2026-3050","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3050","fixed":"1.0.3","last_modified":"2026-02-26T15:15:35.848Z","patch_url":"https://github.com/Horilla-opensource/Horilla-crm/commit/fc5c8e55988e89273012491b5f097b762b474546","primary_source":"","published":"2026-02-24T01:02:09.321Z"},{"affected":"1.0.0; 1.0.1; 1.0.2","affected_versions_present":true,"cve_id":"CVE-2026-3049","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3049","fixed":"1.0.3","last_modified":"2026-02-26T14:47:02.181Z","patch_url":"https://github.com/horilla-opensource/horilla-crm/commit/730b5a44ff060916780c44a4bdbc8ced70a2cd27","primary_source":"","published":"2026-02-24T00:32:11.210Z"},{"affected":">= 1.4.0, < 1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-24039","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24039","fixed":"1.5.0.","last_modified":"2026-01-22T12:30:11.282Z","patch_url":"https://github.com/horilla-opensource/horilla/security/advisories/GHSA-99mq-mhwv-w9qx","primary_source":"","published":"2026-01-22T03:43:41.476Z"},{"affected":">= 1.4.0, < 1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-24038","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24038","fixed":"1.5.0.","last_modified":"2026-01-22T12:33:39.694Z","patch_url":"https://github.com/horilla-opensource/horilla/security/advisories/GHSA-hqpv-ff5v-3hwf","primary_source":"","published":"2026-01-22T03:39:06.216Z"},{"affected":">= 1.4.0, < 1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-24037","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24037","fixed":"1.5.0.","last_modified":"2026-01-22T12:36:02.772Z","patch_url":"https://github.com/horilla-opensource/horilla/security/advisories/GHSA-rqw5-fjm4-rgvm","primary_source":"","published":"2026-01-22T03:31:37.305Z"},{"affected":">= 1.4.0, < 1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-24036","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24036","fixed":"1.5.0.","last_modified":"2026-01-22T12:38:10.451Z","patch_url":"https://github.com/horilla-opensource/horilla/commit/9a585a1588431499092a49d7e82cb77daa4d99ee","primary_source":"","published":"2026-01-22T03:21:32.538Z"},{"affected":">= 1.4.0, < 1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-24035","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24035","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-22T12:41:56.958Z","patch_url":"","primary_source":"","published":"2026-01-22T02:43:10.884Z"},{"affected":"< 1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-24034","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24034","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-22T12:44:21.620Z","patch_url":"","primary_source":"","published":"2026-01-22T02:41:37.702Z"},{"affected":"< 1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-24010","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24010","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-22T12:48:02.914Z","patch_url":"","primary_source":"","published":"2026-01-22T02:37:19.130Z"},{"affected":"< 1.4.0","affected_versions_present":true,"cve_id":"CVE-2025-59832","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59832","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-09-25T15:48:38.332Z","patch_url":"","primary_source":"","published":"2025-09-25T14:45:19.214Z"},{"affected":"< 1.4.0","affected_versions_present":true,"cve_id":"CVE-2025-59525","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59525","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-15T16:06:11.174Z","patch_url":"","primary_source":"","published":"2025-09-24T18:15:12.850Z"},{"affected":"< 1.4.0","affected_versions_present":true,"cve_id":"CVE-2025-59524","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59524","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-09-24T18:46:57.973Z","patch_url":"","primary_source":"","published":"2025-09-24T18:12:55.990Z"},{"affected":"= 1.3.0","affected_versions_present":true,"cve_id":"CVE-2025-48867","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48867","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-09-24T17:36:10.261Z","patch_url":"","primary_source":"","published":"2025-09-24T17:25:42.227Z"},{"affected":"= 1.3.0","affected_versions_present":true,"cve_id":"CVE-2025-48869","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48869","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-09-24T17:26:56.854Z","patch_url":"","primary_source":"","published":"2025-09-24T17:17:40.979Z"},{"affected":"horilla: = 1.3.0","affected_versions_present":true,"cve_id":"CVE-2025-48868","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48868","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-24T18:45:55.219Z","patch_url":"https://github.com/horilla-opensource/horilla/commit/b0aab62b3a5fe6b7114b5c58db129b3744b4d8cc","primary_source":"","published":"2025-09-24T13:51:04.834Z"},{"affected":"<= 1.3","affected_versions_present":true,"cve_id":"CVE-2025-47789","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-47789","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-16T14:51:36.535Z","patch_url":"https://github.com/horilla-opensource/horilla/security/advisories/GHSA-cqp5-xx4j-r468","primary_source":"","published":"2025-05-15T19:50:28.480Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"horilla-opensource"}}
