Vulnerabilities
Latest: CVE-2026-22704 - haxcms-php 11.0.6 Stored XSS Leading to Account Takeover
CVE ID : CVE-2026-22704 Published : Jan. 10, 2026, 7:16 a.m. | 19 minutes ago Description : HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Affected Product:
PHP
Impact:
XSS
Source: Telegram CVE Monitor