Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 CVE-2026-11261

CVE-2026-11261_CVE-2026-11261

Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to p...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11260

CVE-2026-11260_CVE-2026-11260

Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11259

CVE-2026-11259_CVE-2026-11259

Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy v...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11258

CVE-2026-11258_CVE-2026-11258

Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage...

Google Chrome 149.0.7827.53 CVE
MEDIUM 4.3 CVE-2026-11257

CVE-2026-11257_CVE-2026-11257

Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a c...

Google Chrome 149.0.7827.53 CVE
HIGH 7.5 CVE-2026-46493

haxtheweb/haxcms-php uses insecure method for generating salt_CVE-2026-46493

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitabl...

haxtheweb haxcms-php < 26.0.1 CVE
MEDIUM 5.3 CVE-2026-46401

HAX CMS PHP has Insufficient Session Expiration_CVE-2026-46401

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper session termination vulnerabi...

haxtheweb issues < 26.0.0 CVE
HIGH 8.7 CVE-2026-46400

HAXCMS PHP has a File Upload Validation Bypass_CVE-2026-46400

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functi...

haxtheweb haxcms-php >= 11.0.6, < 25.0.0 CVE
HIGH 8.8 CVE-2026-46398

HAX CMS Missing Secure Flag on Cookie_CVE-2026-46398

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.0.0, the haxcms_refresh_tok...

haxtheweb haxcms-php >= 25.0.0, < 26.0.0 CVE
MEDIUM 6.5 CVE-2026-46397

haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0_CVE-2026-46397

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local File Inclusion (LFI) vulnerabi...

haxtheweb haxcms-php < 26.0.0 CVE