📦 Haxcms Nodejs

by Psu

🔍 What is Haxcms Nodejs?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-22704

HIGH CVSS 8.0 Jan 10, 2026

HAX CMS versions 11.0.6 through 24.x are vulnerable to stored cross-site scripting (XSS), allowing attackers to inject malicious scripts that persist in the CMS. When executed, these scripts could lea...

CVE-2025-49141

HIGH CVSS 8.5 Jun 9, 2025

CVE-2025-49141 is an OS command injection vulnerability in HAX CMS PHP's gitImportSite functionality. Authenticated attackers can execute arbitrary commands on the backend server by crafting malicious...

CVE-2025-54139

MEDIUM CVSS 4.3 Jul 23, 2025

HAX CMS versions 11.0.12 and below (NodeJS) and 11.0.7 and below (PHP) lack X-Frame-Options headers, allowing attackers to embed the CMS login page and other sensitive interfaces in iframes. This enab...

CVE-2025-54128

MEDIUM CVSS 6.1 Jul 21, 2025

HAX CMS NodeJS versions 11.0.7 and below have a disabled Content Security Policy (CSP), leaving the application vulnerable to cross-site scripting (XSS) attacks. This allows attackers to inject malici...

CVE-2025-54134

MEDIUM CVSS 6.5 Jul 21, 2025

HAX CMS NodeJS versions 11.0.8 and below crash when authenticated attackers send API requests missing required URL parameters to listFiles and saveFiles endpoints. This denial-of-service vulnerability...

CVE-2025-53642

MEDIUM CVSS 4.8 Jul 11, 2025

This vulnerability in HAXcms backends fails to properly terminate user sessions during logout, allowing attackers to maintain access to authenticated sessions. It affects all users of haxcms-nodejs an...