Haxtheweb

Haxcms-php

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 05.06.2026 19:19:37
  • Zuletzt bearbeitet 05.06.2026 20:48:21

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitable. Version 26.0.1 fixes the issue.

  • EPSS 0.39%
  • Veröffentlicht 05.06.2026 19:15:29
  • Zuletzt bearbeitet 08.06.2026 17:16:51

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functionality in HAXCMS PHP only validates file extensions using a regex pattern without checking the actual ...

  • EPSS 0.18%
  • Veröffentlicht 05.06.2026 19:13:47
  • Zuletzt bearbeitet 05.06.2026 20:48:21

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.0.0, the haxcms_refresh_token cookie is set without the Secure flag. This allows it to be transmitted over unencrypted HTTP, makin...

  • EPSS 0.29%
  • Veröffentlicht 05.06.2026 19:11:52
  • Zuletzt bearbeitet 08.06.2026 17:16:50

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint allows a low-privileged user to read arbitrary files on the ser...

  • EPSS 0.28%
  • Veröffentlicht 05.06.2026 18:32:55
  • Zuletzt bearbeitet 08.06.2026 17:16:52

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to p...

  • EPSS 0.77%
  • Veröffentlicht 05.06.2026 18:26:00
  • Zuletzt bearbeitet 08.06.2026 19:16:45

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vulnerability exists in the Git.php library of the HAXcms PHP backend. The application constructs shell command strings using unsani...

  • EPSS 0.24%
  • Veröffentlicht 05.06.2026 18:24:49
  • Zuletzt bearbeitet 08.06.2026 17:16:50

HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 26.0.0 allows authenticated users to fetch arbitrary internal or local resources and write the...

  • EPSS 0.22%
  • Veröffentlicht 05.06.2026 18:20:25
  • Zuletzt bearbeitet 05.06.2026 20:17:33

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule tha...

  • EPSS 0.27%
  • Veröffentlicht 05.06.2026 18:16:17
  • Zuletzt bearbeitet 09.06.2026 16:16:41

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0.0, the gitlist plugin is exposed to unauthenticated users, allowing unauthenticated browsing of git repositories and git history....

  • EPSS 0.29%
  • Veröffentlicht 05.06.2026 18:13:15
  • Zuletzt bearbeitet 08.06.2026 17:16:50

HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file overwrite vulnerability. An attacker can exploit this vulnerability to configure malicious Git filter co...