CVE 8.1 HIGH

haxcms-php 11.0.6 Stored XSS Leading to Account Takeover_CVE-2026-22704

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Description

HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.

Basic Information

ID CVE-2026-22704
Source GitHub_M
Published Jan 10, 2026 at 06:22
Modified Jan 10, 2026 at 06:23

Affected Product

Vendor haxtheweb
Product issues
Version >= 11.0.6, < 25.0.0
Affected Versions haxtheweb issues >= 11.0.6, < 25.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.