216.73.217.22

CVE-2026-46396

· Published 05/06/2026 19:16 · Modified 05/06/2026 19:20

Labels: CVE-2026-46396 2026-06-05CVE-2026-46396CWE-79[email protected]

Essential information

Published
05/06/2026 19:16
Modified
05/06/2026 19:20
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of `<iframe>` elements. The application allows `javascript:` URIs in the `src` attribute, which are executed when a malicious page is viewed. This enables attackers to execute arbitrary JavaScript in the context of the victim’s browser and access sensitive data exposed to client-side scripts. Version 26.0.0 fixes the issue.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
hax / hax cms cpe:2.3:a:hax:hax_cms:<26.0.0:*:*:*:*:*:*:*

References