VendorsPsuhaxcms-phpall versions
Vulnerabilities

Psu The Pennsylvania State University HAXcms-PHP

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-32028
HAX CMS PHP allows Insecure File Upload to Lead to Remote Code Execution
Published 2025-04-08 · Analyzed
9.9EPSS 0.020
CVE-2025-49141
HaxCMS-PHP Command Injection Vulnerability
Published 2025-06-09 · Analyzed
8.8EPSS 0.015
CVE-2025-49137
Hax CMS Stored Cross-Site Scripting vulnerability
Published 2025-06-09 · Analyzed
8.5EPSS 0.003
CVE-2025-54378
HAX CMS Backend Lacks Comprehensive Authorization Checks
Published 2025-07-26 · Analyzed
8.3EPSS 0.005
CVE-2025-49138
HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter
Published 2025-06-09 · Analyzed
6.5EPSS 0.005
CVE-2025-49139
@haxtheweb/haxcms-nodejs Iframe Phishing vulnerability
Published 2025-06-09 · Analyzed
6.5EPSS 0.004
CVE-2025-53642
haxcms-nodejs and haxcms-php Improperly Terminate Sessions
Published 2025-07-11 · Analyzed
6.5EPSS 0.002
CVE-2025-54139
HAX CMS' application pages are vulnerable to clickjacking
Published 2025-07-22 · Analyzed
6.1EPSS 0.003