HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
Metrics
Affected Vendors & Products
References
History
Sat, 10 Jan 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0. | |
| Title | haxcms-php 11.0.6 Stored XSS Leading to Account Takeover | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-10T06:23:09.987Z
Reserved: 2026-01-08T19:23:09.857Z
Link: CVE-2026-22704
No data.
Status : Received
Published: 2026-01-10T07:16:03.200
Modified: 2026-01-10T07:16:03.200
Link: CVE-2026-22704
No data.
OpenCVE Enrichment
No data.