Stored XSS Vulnerability in HAX CMS by HAX Technologies
CVE-2026-22704
8.1HIGH
What is CVE-2026-22704?
HAX CMS, a content management system leveraging PHP or NodeJs backends, is susceptible to a stored XSS vulnerability in versions 11.0.6 through 24.0.0. This flaw can facilitate malicious actors to execute scripts on behalf of users, potentially leading to unauthorized account access and control. Developers are urged to upgrade to version 25.0.0, where this vulnerability has been effectively mitigated.
Affected Version(s)
issues >= 11.0.6, < 25.0.0
