Description
HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
Published: 2026-01-10
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via Stored XSS
Action: Immediate Patch
AI Analysis

Impact

HAX CMS versions 11.0.6 up to (but not including) 25.0.0 contain a stored cross-site scripting flaw that allows an attacker to inject malicious script into the CMS database. The injected payload can execute in the context of authenticated users, potentially enabling the theft of user credentials or direct takeover of their administrative accounts. This vulnerability is classified as CWE-79 and provides a direct path from a content author or user with write permissions to an attacker gaining persistent access to privileged sessions.

Affected Systems

The issue affects the haxtheweb haxcms-nodejs product. All installations of version 11.0.6 through 24.x.x are vulnerable; the fix was released in v25.0.0. No other products or versions are indicated as impacted.

Risk and Exploitability

The CVSS score is 8.1, indicating a high severity. The EPSS score is below 1%, suggesting a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web-based: an attacker logs into the CMS (or obtains a user account with authoring rights), injects malicious script through a content field, and later an authenticated user views that content, causing the payload to run in their browser. This execution then allows the attacker to hijack the session or exfiltrate information.

Generated by OpenCVE AI on April 18, 2026 at 16:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade haxcms-nodejs to v25.0.0 or later, as the patch removes the stored XSS vector.
  • Redeploy the updated CMS instance to ensure the patch takes effect.
  • If an upgrade is not immediately possible, apply input sanitization to all content fields (e.g., using DOMPurify) and enforce a strict Content Security Policy that blocks inline scripts and eval usage.

Generated by OpenCVE AI on April 18, 2026 at 16:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3fm2-xfq7-7778 HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover
History

Thu, 05 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Psu
Psu haxcms-nodejs
CPEs cpe:2.3:a:psu:haxcms-nodejs:11.0.6:*:*:*:*:node.js:*:*
Vendors & Products Psu
Psu haxcms-nodejs

Tue, 13 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Title haxcms-php 11.0.6 Stored XSS Leading to Account Takeover HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover
References

Mon, 12 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Haxtheweb
Haxtheweb hax
Vendors & Products Haxtheweb
Haxtheweb hax

Mon, 12 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 10 Jan 2026 06:30:00 +0000

Type Values Removed Values Added
Description HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
Title haxcms-php 11.0.6 Stored XSS Leading to Account Takeover
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-13T15:09:03.814Z

Reserved: 2026-01-08T19:23:09.857Z

Link: CVE-2026-22704

cve-icon Vulnrichment

Updated: 2026-01-12T13:41:18.414Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-10T07:16:03.200

Modified: 2026-02-05T20:59:55.283

Link: CVE-2026-22704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T16:45:05Z

Weaknesses