Insecure Default Configuration in HAXcms with NodeJS Backend
CVE-2025-54127

9.3CRITICAL

Key Information:

Vendor

Haxtheweb

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-54127?

The HAXcms with a NodeJS backend is affected by an insecure default configuration that allows users to start the server in any HAXsite without proper authorization or authentication checks. The default setting for HAXcms versions 11.0.6 and earlier allows for 'HAXCMS_DISABLE_JWT_CHECKS' to be enabled, leading to configurations that lack session authentication. This vulnerability can be exploited if the software is deployed without proper modifications, potentially exposing sensitive data and functionalities. The issue has been resolved in version 11.0.7.

Affected Version(s)

issues < 11.0.7

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54127 : Insecure Default Configuration in HAXcms with NodeJS Backend