HAX CMS has a stored XSS via <iframe> that allows access to sensitive client-side data and account takeover
CVE-2026-46396

9.3CRITICAL

Key Information:

Vendor

Haxtheweb

Vendor
CVE Published:
5 June 2026

What is CVE-2026-46396?

HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of <iframe> elements. The application allows javascript: URIs in the src attribute, which are executed when a malicious page is viewed. This enables attackers to execute arbitrary JavaScript in the context of the victim’s browser and access sensitive data exposed to client-side scripts. Version 26.0.0 fixes the issue.

Affected Version(s)

haxcms-nodejs < 26.0.0

iframe-loader < 26.0.0

video-player < 26.0.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.