PT-2025-30344 · Hax Cms · Hax Cms

Asareynolds

·

Published

2025-07-21

·

Updated

2025-07-22

·

CVE-2025-54127

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HAXcms versions prior to 11.0.7
Description HAXcms with a nodejs backend allows users to start the server in any HAXsite or HAXcms instance. The NodeJS version of HAXcms, in versions 11.0.6 and below, uses an insecure default configuration intended for local development. This configuration lacks session authentication because the HAXCMS DISABLE JWT CHECKS variable is set to true by default.
Recommendations HAXcms versions prior to 11.0.7: Update to version 11.0.7 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-54127
GHSA-F38F-JVQJ-MFG6

Affected Products

Hax Cms