vciy

CVEs we hold for Haxtheweb

Records whose assigning authority named Haxtheweb as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-48527HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpointhaxtheweb haxcms-php
CVE-2026-46511HAXcms: Mass Token Exfiltration and Cross-Tenant Hijackhaxtheweb haxcms-php
CVE-2026-46496HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token thefthaxtheweb video-player
CVE-2026-46493haxtheweb/haxcms-php uses insecure method for generating salthaxtheweb haxcms-php
CVE-2026-46401HAX CMS PHP has Insufficient Session Expirationhaxtheweb issues
CVE-2026-46400HAXCMS PHP has a File Upload Validation Bypasshaxtheweb haxcms-php
CVE-2026-46399Authenticated Remote Code Execution via File Overwritehaxtheweb haxcms-php
CVE-2026-46398HAX CMS Missing Secure Flag on Cookiehaxtheweb haxcms-php
CVE-2026-46397haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0haxtheweb haxcms-nodejs
CVE-2026-46396HAX CMS has a stored XSS via <iframe> that allows access to sensitive client-side data and account takeoverhaxtheweb iframe-loader
CVE-2026-46395HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementationhaxtheweb haxcms-nodejs
CVE-2026-46394HAX CMS Vulnerable to Command Injection using Git.phphaxtheweb haxcms-php
CVE-2026-46393HAXcms createSite SSRF Enables Arbitrary File Readhaxtheweb haxcms-php
CVE-2026-46392HAX CMS PHP Has a Stored XSS via Case-Sensitivity Mismatch in HTML Upload Validationhaxtheweb haxcms-php
CVE-2026-46391HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apishaxtheweb @haxtheweb/open-apis
CVE-2026-46390HAX CMS has Unauthenticated Git Access via User-Controlled Keyhaxtheweb haxcms-php
CVE-2026-46357HAX CMS NodeJS application Vulnerable to Denial of Service using Malicious Import Requesthaxtheweb haxcms-nodejs
CVE-2026-35185HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addresseshaxtheweb HAXiam
CVE-2026-22704HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeoverhaxtheweb issues
CVE-2025-54378HAX CMS Backend Lacks Comprehensive Authorization Checkshaxtheweb issues
CVE-2025-54139HAX CMS' application pages are vulnerable to clickjackinghaxtheweb issues
CVE-2025-54137NodeJS version of the HAX CMS application is distributed with Default Secretshaxtheweb issues
CVE-2025-54134HAX CMS NodeJs's Improper Error Handling Leads to Denial of Servicehaxtheweb issues
CVE-2025-54129HAXiam allows for User Enumerationhaxtheweb issues
CVE-2025-54128HAX CMS NodeJs's Disabled Content Security Policy Enables Cross-Site Scriptinghaxtheweb issues
CVE-2025-54127HAXcms's Insecure Default Configuration Leads to Unauthenticated Accesshaxtheweb issues
CVE-2025-53642haxcms-nodejs and haxcms-php Improperly Terminate Sessionshaxtheweb issues
CVE-2025-49141HaxCMS-PHP Command Injection Vulnerabilityhaxtheweb issues
CVE-2025-49139@haxtheweb/haxcms-nodejs Iframe Phishing vulnerabilityhaxtheweb issues
CVE-2025-49138HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameterhaxtheweb issues
CVE-2025-49137Hax CMS Stored Cross-Site Scripting vulnerabilityhaxtheweb issues
CVE-2025-48996Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpointhaxtheweb issues
CVE-2025-32028HAX CMS PHP allows Insecure File Upload to Lead to Remote Code Executionhaxtheweb issues

33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.