Cross-Site Scripting Vulnerability in HAX CMS by HAX Technology
CVE-2025-49139
What is CVE-2025-49139?
HAX CMS prior to version 11.0.0 contains a vulnerability that allows authenticated users to create a website block that loads an external URL in an iframe. This functionality can be exploited by an attacker who controls the target URL, enabling them to conduct phishing attacks through malicious HAX sites. When unsuspecting users visit a compromised site, their browsers will interact with the attacker's server, allowing for the potential theft of sensitive information such as credentials. Version 11.0.0 has remedied this issue with a patch.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
issues < 11.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
