CVE-2025-54127 is a critical vulnerability affecting HAXcms with a NodeJS backend, specifically versions 11.0.6 and below of psu haxcms_nodejs. It stems from an insecure default configuration intended for local development, which disables JWT authentication checks. This allows an unauthenticated attacker to gain full control over the affected HAXcms instance, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.0.7CPE matchmatch criteria | cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.