Psu maintains a modest but prominent portfolio centered on the HAXcms web content management platform, available in both Node.js and PHP variants, alongside related products such as HAXiAM. The vendor's vulnerabilities skew toward serious outcomes and recur through application-layer weakness classes including cross-site scripting, improper UI-layer restrictions, external path control, and access-control defects that are typical of web-facing content and authentication systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Psu over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22704MEDIUM HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. | Jan 10, 2026 | 5.4 | 32 | NO | YES |
CVE-2025-32028CRITICAL HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.p | Apr 8, 2025 | 9.9 | 28 | NO | NO |
CVE-2025-54127CRITICAL HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default c | Jul 21, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-54378HIGH HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below of haxcms-php, API en | Jul 26, 2025 | 8.3 | 26 | NO | NO |
CVE-2026-35185HIGH HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including | Apr 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-49141HIGH HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string from a POST request | Jun 9, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-54137HIGH HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were distributed with hardcoded default credentials for the user and | Jul 22, 2025 | 7.3 | 19 | NO | NO |
CVE-2025-54134MEDIUM HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated att | Jul 21, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-54128MEDIUM HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Po | Jul 21, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-53642MEDIUM haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the appli | Jul 11, 2025 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Psu.
Media articles that mention a CVE ID that affects a product developed by Psu — matched by CVE ID, not by vendor name.