HAX是HAX The Web开源的一个HAX+CMS使用PHP后端管理的微型网站。 HAX 11.0.0之前版本存在安全漏洞,该漏洞源于网站块目标URL控制不当,可能导致钓鱼攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-49141 | 8.6 HIGH | HaxCMS-PHP Command Injection Vulnerability |
| CVE-2025-49137 | 8.5 HIGH | Hax CMS Stored Cross-Site Scripting vulnerability |
| CVE-2025-49138 | 6.5 MEDIUM | HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter |
No comments yet