All 7 CVE vulnerabilities found in haxcms-php, with AI-generated Chinese analysis, references, and POCs.
Vendor: haxtheweb
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-46493 | haxtheweb/haxcms-php uses insecure method for generating salt CWE-338 | 7.5 | High | 2026-06-05 |
| CVE-2026-46400 | HAXCMS PHP has a File Upload Validation Bypass CWE-434 | - | - | 2026-06-05 |
| CVE-2026-46398 | HAX CMS Missing Secure Flag on Cookie CWE-614 | - | - | 2026-06-05 |
| CVE-2026-46397 | haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0 CWE-22 | 6.5 | Medium | 2026-06-05 |
| CVE-2026-46394 | HAX CMS Vulnerable to Command Injection using Git.php CWE-78 | - | - | 2026-06-05 |
| CVE-2026-46392 | HAX CMS PHP Has a Stored XSS via Case-Sensitivity Mismatch in HTML Upload Validation CWE-178 | 8.7 | High | 2026-06-05 |
| CVE-2026-46390 | HAX CMS has Unauthenticated Git Access via User-Controlled Key CWE-639 | - | - | 2026-06-05 |
All 7 known CVE vulnerabilities affecting haxcms-php with full Chinese analysis, references, and POCs where available.