CVE-2026-22704

HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:psu:haxcms-nodejs:11.0.6:*:*:*:*:node.js:*:*

History

05 Feb 2026, 20:59

Type Values Removed Values Added
CPE cpe:2.3:a:psu:haxcms-nodejs:11.0.6:*:*:*:*:node.js:*:*
First Time Psu
Psu haxcms-nodejs
References () https://github.com/haxtheweb/haxcms-nodejs/commit/317a8ae29f88be389f7cfeffaef416957122d97e - () https://github.com/haxtheweb/haxcms-nodejs/commit/317a8ae29f88be389f7cfeffaef416957122d97e - Patch
References () https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v25.0.0 - () https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v25.0.0 - Release Notes
References () https://github.com/haxtheweb/issues/security/advisories/GHSA-3fm2-xfq7-7778 - () https://github.com/haxtheweb/issues/security/advisories/GHSA-3fm2-xfq7-7778 - Exploit, Vendor Advisory

13 Jan 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/haxtheweb/haxcms-nodejs/commit/317a8ae29f88be389f7cfeffaef416957122d97e -

10 Jan 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-10 07:16

Updated : 2026-02-05 20:59


NVD link : CVE-2026-22704

Mitre link : CVE-2026-22704

CVE.ORG link : CVE-2026-22704


JSON object : View

Products Affected

psu

  • haxcms-nodejs
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')