VendorsPsuhaxcms-nodejsany version
Vulnerabilities

Psu The Pennsylvania State University HAXcms-nodejs any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2025-54127
HAXcms's Insecure Default Configuration Leads to Unauthenticated Access
Published 2025-07-21 · Analyzed
9.8EPSS 0.004
CVE-2025-49141
HaxCMS-PHP Command Injection Vulnerability
Published 2025-06-09 · Analyzed
8.8EPSS 0.015
CVE-2025-49137
Hax CMS Stored Cross-Site Scripting vulnerability
Published 2025-06-09 · Analyzed
8.5EPSS 0.003
CVE-2025-54378
HAX CMS Backend Lacks Comprehensive Authorization Checks
Published 2025-07-26 · Analyzed
8.3EPSS 0.005
CVE-2025-54137
NodeJS version of the HAX CMS application is distributed with Default Secrets
Published 2025-07-22 · Analyzed
7.3EPSS 0.003
CVE-2025-54128
HAX CMS NodeJs's Disabled Content Security Policy Enables Cross-Site Scripting
Published 2025-07-21 · Analyzed
7.2EPSS 0.002
CVE-2025-54134
HAX CMS NodeJs's Improper Error Handling Leads to Denial of Service
Published 2025-07-21 · Analyzed
7.1EPSS 0.004
CVE-2025-49139
@haxtheweb/haxcms-nodejs Iframe Phishing vulnerability
Published 2025-06-09 · Analyzed
6.5EPSS 0.004
CVE-2025-53642
haxcms-nodejs and haxcms-php Improperly Terminate Sessions
Published 2025-07-11 · Analyzed
6.5EPSS 0.002
CVE-2025-54139
HAX CMS' application pages are vulnerable to clickjacking
Published 2025-07-22 · Analyzed
6.1EPSS 0.003