Haxcms Nodejs
Vendor:
First CVE: Jun 9, 2025 · Active for 1 year
11
Total CVEs
More Total CVEs than 89% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Haxcms Nodejs over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2025
13 months ago
Most Recent CVE
Jan 10, 2026
195 days ago
CVE Severity & Scoring
Haxcms Nodejs11 CVEs
64%
27%
9%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low4 (36.4%)
High0 (0.0%)
None7 (63.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22704MEDIUM HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. | Jan 10, 2026 | 5.4 | 32 | NO | YES |
CVE-2025-54127CRITICAL HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default c | Jul 21, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-54378HIGH HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below of haxcms-php, API en | Jul 26, 2025 | 8.3 | 26 | NO | NO |
CVE-2025-49141HIGH HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string from a POST request | Jun 9, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-54137HIGH HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were distributed with hardcoded default credentials for the user and | Jul 22, 2025 | 7.3 | 19 | NO | NO |
CVE-2025-54134MEDIUM HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated att | Jul 21, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-54128MEDIUM HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Po | Jul 21, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-53642MEDIUM haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the appli | Jul 11, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-49137MEDIUM HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user input, allowing for the | Jun 9, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-54139MEDIUM HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all p | Jul 23, 2025 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Haxcms Nodejs
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.0.6 | 1 | 5.4 | 1.0% | 0 | 1 |