PT-2026-47028 · Hax Cms · Hax Cms+1

CVE-2026-46390

·

Published

2026-06-05

·

Updated

2026-06-06

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions HAX CMS versions 2.0.0 through 25.x
Description The gitlist plugin is exposed to unauthenticated users, which allows them to browse git repositories and git history without authentication.
Recommendations Update to version 26.0.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46390

Affected Products

Hax Cms
Gitlist