Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2026-46496

HAX CMS: Stored XSS via ‘‘ component allows arbitrary JavaScript execution and token theft_CVE-2026-46496

HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to ...

haxtheweb haxcms-nodejs < 26.0.0 CVE
CRITICAL 9.4 CVE-2026-46399

Authenticated Remote Code Execution via File Overwrite_CVE-2026-46399

HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file o...

haxtheweb haxcms-nodejs < 26.0.0 CVE
CRITICAL 9.3 CVE-2026-46396

HAX CMS has a stored XSS via