HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | haxcms-php 11.0.6 Stored XSS Leading to Account Takeover | HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover |
| References |
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Haxtheweb
Haxtheweb hax |
|
| Vendors & Products |
Haxtheweb
Haxtheweb hax |
Mon, 12 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 10 Jan 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0. | |
| Title | haxcms-php 11.0.6 Stored XSS Leading to Account Takeover | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-01-10T06:22:45.076Z
Updated: 2026-01-13T15:09:03.814Z
Reserved: 2026-01-08T19:23:09.857Z
Link: CVE-2026-22704
Updated: 2026-01-12T13:41:18.414Z
Status : Awaiting Analysis
Published: 2026-01-10T07:16:03.200
Modified: 2026-01-13T15:16:01.087
Link: CVE-2026-22704
No data.