Browse all 33 CVE security advisories affecting haxtheweb. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Haxtheweb primarily develops web applications and APIs for enterprise clients, with a core focus on custom business solutions. Historically, the organization has been associated with multiple remote code execution, cross-site scripting, and privilege escalation vulnerabilities across its products. Security assessments reveal consistent flaws in input validation and authentication mechanisms. While no major public breaches have been directly attributed to haxtheweb, its cumulative 16 CVEs indicate systemic security weaknesses in development practices. The organization's codebase frequently demonstrates inadequate sanitization of user inputs and misconfigured access controls, creating persistent exposure vectors for attackers.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-49137 | Hax CMS Stored Cross-Site Scripting vulnerability — issues CWE-79 | 8.5 | High | 2025-06-09 |
| CVE-2025-48996 | Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint — issues CWE-201 | 5.3 | Medium | 2025-06-02 |
| CVE-2025-32028 | HAX CMS PHP allows Insecure File Upload to Lead to Remote Code Execution — issues CWE-434 | 10.0 | Critical | 2025-04-08 |
This page lists every published CVE security advisory associated with haxtheweb. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.