8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Description
HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
Basic Information
ID
CVE-2026-22704
Source
GitHub_M
Published
Jan 10, 2026 at 06:22
Modified
Jan 10, 2026 at 06:23
Affected Product
Vendor
haxtheweb
Product
issues
Version
>= 11.0.6, < 25.0.0
Affected Versions
haxtheweb issues >= 11.0.6, < 25.0.0