HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
History

Sat, 10 Jan 2026 06:30:00 +0000

Type Values Removed Values Added
Description HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
Title haxcms-php 11.0.6 Stored XSS Leading to Account Takeover
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-10T06:23:09.987Z

Reserved: 2026-01-08T19:23:09.857Z

Link: CVE-2026-22704

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-10T07:16:03.200

Modified: 2026-01-10T07:16:03.200

Link: CVE-2026-22704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.