Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3fm2-xfq7-7778 | HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 13 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | haxcms-php 11.0.6 Stored XSS Leading to Account Takeover | HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover |
| References |
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Haxtheweb
Haxtheweb hax |
|
| Vendors & Products |
Haxtheweb
Haxtheweb hax |
Mon, 12 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 10 Jan 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0. | |
| Title | haxcms-php 11.0.6 Stored XSS Leading to Account Takeover | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-13T15:09:03.814Z
Reserved: 2026-01-08T19:23:09.857Z
Link: CVE-2026-22704
Updated: 2026-01-12T13:41:18.414Z
Status : Awaiting Analysis
Published: 2026-01-10T07:16:03.200
Modified: 2026-01-13T15:16:01.087
Link: CVE-2026-22704
No data.
OpenCVE Enrichment
Updated: 2026-01-12T14:36:27Z
Github GHSA