HAXCMS是HAX The Web开源的一个内容管理系统。 HAX CMS PHP 11.0.6版本至25.0.0之前版本存在代码问题漏洞,该漏洞源于文件上传功能仅使用正则表达式验证文件扩展名而未检查实际文件内容或MIME类型,可能导致攻击者上传伪装成合法图像文件的恶意文件,实现远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| haxtheweb | haxcms-php | >= 11.0.6, < 25.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| haxtheweb | haxcms-php | >= 11.0.6, < 25.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46392 | 8.7 HIGH | HAX CMS PHP Has a Stored XSS via Case-Sensitivity Mismatch in HTML Upload Validation |
| CVE-2026-46493 | 7.5 HIGH | haxtheweb/haxcms-php uses insecure method for generating salt |
| CVE-2026-46357 | 6.5 MEDIUM | HAX CMS NodeJS application Vulnerable to Denial of Service using Malicious Import Request |
| CVE-2026-46397 | 6.5 MEDIUM | haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0 |
| CVE-2026-46396 | HAX CMS has a stored XSS via <iframe> that allows access to sensitive client-side data and | |
| CVE-2026-46401 | HAX CMS PHP has Insufficient Session Expiration | |
| CVE-2026-46390 | HAX CMS has Unauthenticated Git Access via User-Controlled Key | |
| CVE-2026-46394 | HAX CMS Vulnerable to Command Injection using Git.php | |
| CVE-2026-46496 | HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution a | |
| CVE-2026-46398 | HAX CMS Missing Secure Flag on Cookie | |
| CVE-2026-46395 | HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation | |
| CVE-2026-46511 | HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack | |
| CVE-2026-46391 | HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis | |
| CVE-2026-46393 | HAXcms createSite SSRF Enables Arbitrary File Read | |
| CVE-2026-46399 | Authenticated Remote Code Execution via File Overwrite |
No comments yet