

HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead …
Published:
9 January 2026 at 23:00:00
Alert date:
10 January 2026 at 13:10:58
Source:
nvd.nist.gov
HAX CMS, a platform for managing microsite universe with PHP or NodeJs backends, contains a stored XSS vulnerability in versions 11.0.6 to before 25.0.0. The vulnerability could lead to account takeover attacks. The issue affects both PHP and NodeJs implementations of the content management system. A patch has been released in version 25.0.0 to address this security flaw. Organizations using affected versions should upgrade immediately to prevent potential exploitation.
Technical details
Mitigation steps:
Affected products:
HAX CMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-22704
https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v25.0.0
https://github.com/haxtheweb/issues/security/advisories/GHSA-3fm2-xfq7-7778
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.

