Haxcms Php
Vendor:
First CVE: Apr 8, 2025 · Active for 1 year
8
Total CVEs
More Total CVEs than 85% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Haxcms Php over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2025
15 months ago
Most Recent CVE
Jul 26, 2025
363 days ago
CVE Severity & Scoring
Haxcms Php8 CVEs
63%
25%
13%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None4 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32028CRITICAL HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.p | Apr 8, 2025 | 9.9 | 28 | NO | NO |
CVE-2025-54378HIGH HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below of haxcms-php, API en | Jul 26, 2025 | 8.3 | 26 | NO | NO |
CVE-2025-49141HIGH HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string from a POST request | Jun 9, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-53642MEDIUM haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the appli | Jul 11, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-49137MEDIUM HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user input, allowing for the | Jun 9, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-54139MEDIUM HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all p | Jul 23, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-49139MEDIUM HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can create a website block to load another si | Jun 9, 2025 | 6.5 | 18 | NO | NO |
CVE-2025-49138MEDIUM HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS sav | Jun 9, 2025 | 6.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Haxcms Php
Top CWEs
Versions
No cataloged versions.