CVEs we hold for Haxtheweb
Records whose assigning authority named Haxtheweb as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-48527HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpointhaxtheweb haxcms-php
CVE-2026-46496HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token thefthaxtheweb video-player
CVE-2026-46397haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0haxtheweb haxcms-nodejs
CVE-2026-46396HAX CMS has a stored XSS via <iframe> that allows access to sensitive client-side data and account takeoverhaxtheweb iframe-loader
CVE-2026-46395HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementationhaxtheweb haxcms-nodejs
CVE-2026-46392HAX CMS PHP Has a Stored XSS via Case-Sensitivity Mismatch in HTML Upload Validationhaxtheweb haxcms-php
CVE-2026-46391HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apishaxtheweb @haxtheweb/open-apis
CVE-2026-46357HAX CMS NodeJS application Vulnerable to Denial of Service using Malicious Import Requesthaxtheweb haxcms-nodejs
CVE-2026-35185HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addresseshaxtheweb HAXiam
CVE-2025-54137NodeJS version of the HAX CMS application is distributed with Default Secretshaxtheweb issues
CVE-2025-54128HAX CMS NodeJs's Disabled Content Security Policy Enables Cross-Site Scriptinghaxtheweb issues
CVE-2025-54127HAXcms's Insecure Default Configuration Leads to Unauthenticated Accesshaxtheweb issues
CVE-2025-49138HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameterhaxtheweb issues
CVE-2025-48996Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpointhaxtheweb issues
CVE-2025-32028HAX CMS PHP allows Insecure File Upload to Lead to Remote Code Executionhaxtheweb issues
33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.