CVE-2026-22704

HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:psu:haxcms-nodejs:11.0.6:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:20

Type Values Removed Values Added
Summary
  • (es) HAX CMS ayuda a gestionar el universo de micrositios con backends de PHP o NodeJs. En las versiones 11.0.6 hasta antes de la 25.0.0, HAX CMS es vulnerable a XSS almacenado, lo que podría llevar a la toma de control de cuentas. Este problema ha sido parcheado en la versión 25.0.0.

05 Feb 2026, 20:59

Type Values Removed Values Added
References () https://github.com/haxtheweb/haxcms-nodejs/commit/317a8ae29f88be389f7cfeffaef416957122d97e - () https://github.com/haxtheweb/haxcms-nodejs/commit/317a8ae29f88be389f7cfeffaef416957122d97e - Patch
References () https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v25.0.0 - () https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v25.0.0 - Release Notes
References () https://github.com/haxtheweb/issues/security/advisories/GHSA-3fm2-xfq7-7778 - () https://github.com/haxtheweb/issues/security/advisories/GHSA-3fm2-xfq7-7778 - Exploit, Vendor Advisory
CPE cpe:2.3:a:psu:haxcms-nodejs:11.0.6:*:*:*:*:node.js:*:*
First Time Psu
Psu haxcms-nodejs

13 Jan 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/haxtheweb/haxcms-nodejs/commit/317a8ae29f88be389f7cfeffaef416957122d97e -

10 Jan 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-10 07:16

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22704

Mitre link : CVE-2026-22704

CVE.ORG link : CVE-2026-22704


JSON object : View

Products Affected

psu

  • haxcms-nodejs
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')