9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Description
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of <iframe> elements. The application allows `javascript:` URIs in the `src` attribute, which are executed when a malicious page is viewed. This enables attackers to execute arbitrary JavaScript in the context of the victimβs browser and access sensitive data exposed to client-side scripts. Version 26.0.0 fixes the issue.
AI Analysis
Stored cross-site scripting (XSS) vulnerability due to improper sanitization of iframe elements, allowing attackers to execute arbitrary JavaScript and access sensitive client-side data.
Basic Information
ID
CVE-2026-46396
Source
GitHub_M
Published
Jun 5, 2026 at 18:44
Affected Product
Vendor
haxtheweb
Product
haxcms-nodejs
Version
< 26.0.0
Affected Versions
haxtheweb haxcms-nodejs < 26.0.0
haxtheweb video-player < 26.0.0
haxtheweb iframe-loader < 26.0.0
haxtheweb video-player < 26.0.0
haxtheweb iframe-loader < 26.0.0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
haxtheweb
Product
HAX CMS
Version
< 26.0.0