PT-2026-2254 · Hax Cms · Hax Cms

August829

·

Published

2026-01-10

·

Updated

2026-02-05

·

CVE-2026-22704

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HAX CMS versions 11.0.6 through 24.x HAX CMS versions prior to 25.0.0
Description HAX CMS, which manages microsite universes with PHP or NodeJs backends, is subject to a stored cross-site scripting (XSS) issue. This flaw potentially allows for account takeover. The issue affects versions using PHP or NodeJs backends. Stored XSS occurs when malicious scripts are injected into a website and stored on the server, allowing them to be executed when other users visit the affected pages.
Recommendations HAX CMS versions 11.0.6 through 24.x should be upgraded to version 25.0.0 or later. HAX CMS versions prior to 25.0.0 should be upgraded to version 25.0.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-22704
GHSA-3FM2-XFQ7-7778

Affected Products

Hax Cms