← Back

CVE-2026-22704

nvd nist
Published: Jan 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.

Affected (1)

Products: Psu: Haxcms Nodejs
1 product
Haxcms Nodejs
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0.6

References (3)

Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
ExploitVendor Advisory

Timeline

No history available yet.