HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
References
| Link | Resource |
|---|---|
| https://github.com/haxtheweb/haxcms-nodejs/commit/317a8ae29f88be389f7cfeffaef416957122d97e | Patch |
| https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v25.0.0 | Release Notes |
| https://github.com/haxtheweb/issues/security/advisories/GHSA-3fm2-xfq7-7778 | Exploit Vendor Advisory |
Configurations
History
05 Feb 2026, 20:59
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:psu:haxcms-nodejs:11.0.6:*:*:*:*:node.js:*:* | |
| First Time |
Psu
Psu haxcms-nodejs |
|
| References | () https://github.com/haxtheweb/haxcms-nodejs/commit/317a8ae29f88be389f7cfeffaef416957122d97e - Patch | |
| References | () https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v25.0.0 - Release Notes | |
| References | () https://github.com/haxtheweb/issues/security/advisories/GHSA-3fm2-xfq7-7778 - Exploit, Vendor Advisory |
13 Jan 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Jan 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-10 07:16
Updated : 2026-02-05 20:59
NVD link : CVE-2026-22704
Mitre link : CVE-2026-22704
CVE.ORG link : CVE-2026-22704
JSON object : View
Products Affected
psu
- haxcms-nodejs
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
