CVE-2026-46357
- EPSS 0.24%
- Veröffentlicht 05.06.2026 19:21:03
- Zuletzt bearbeitet 09.06.2026 16:16:41
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS application crashes when an authenticated attacker sends a specially crafted site creation request to the createSite endpoint. A single r...
CVE-2026-46397
- EPSS 0.29%
- Veröffentlicht 05.06.2026 19:11:52
- Zuletzt bearbeitet 08.06.2026 17:16:50
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint allows a low-privileged user to read arbitrary files on the ser...
CVE-2026-46496
- EPSS 0.23%
- Veröffentlicht 05.06.2026 18:46:36
- Zuletzt bearbeitet 05.06.2026 20:17:34
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of the `<video-player>` component. The component allows `javascript...
CVE-2026-46396
- EPSS 0.23%
- Veröffentlicht 05.06.2026 18:44:28
- Zuletzt bearbeitet 09.06.2026 16:16:42
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of `<iframe>` elements. The application allows `javascript:` URIs i...
CVE-2026-46511
- EPSS 0.28%
- Veröffentlicht 05.06.2026 18:32:55
- Zuletzt bearbeitet 08.06.2026 17:16:52
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to p...
CVE-2026-46395
- EPSS 0.3%
- Veröffentlicht 05.06.2026 18:27:54
- Zuletzt bearbeitet 05.06.2026 20:17:33
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unauthenticated ...
CVE-2026-46393
- EPSS 0.24%
- Veröffentlicht 05.06.2026 18:24:49
- Zuletzt bearbeitet 08.06.2026 17:16:50
HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 26.0.0 allows authenticated users to fetch arbitrary internal or local resources and write the...
CVE-2026-46399
- EPSS 0.29%
- Veröffentlicht 05.06.2026 18:13:15
- Zuletzt bearbeitet 08.06.2026 17:16:50
HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file overwrite vulnerability. An attacker can exploit this vulnerability to configure malicious Git filter co...
CVE-2026-48527
- EPSS 0.23%
- Veröffentlicht 29.05.2026 12:26:07
- Zuletzt bearbeitet 29.05.2026 16:29:11
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission...
CVE-2025-54378
- EPSS 0.45%
- Veröffentlicht 26.07.2025 03:27:34
- Zuletzt bearbeitet 21.08.2025 20:54:52
HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below of haxcms-php, API endpoints do not perform authorization checks when interacting with a re...