Browse all 33 CVE security advisories affecting haxtheweb. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Haxtheweb primarily develops web applications and APIs for enterprise clients, with a core focus on custom business solutions. Historically, the organization has been associated with multiple remote code execution, cross-site scripting, and privilege escalation vulnerabilities across its products. Security assessments reveal consistent flaws in input validation and authentication mechanisms. While no major public breaches have been directly attributed to haxtheweb, its cumulative 16 CVEs indicate systemic security weaknesses in development practices. The organization's codebase frequently demonstrates inadequate sanitization of user inputs and misconfigured access controls, creating persistent exposure vectors for attackers.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-46493 | haxtheweb/haxcms-php uses insecure method for generating salt — haxcms-php CWE-338 | 7.5 | High | 2026-06-05 |
| CVE-2026-46400 | HAXCMS PHP has a File Upload Validation Bypass — haxcms-php CWE-434 | - | - | 2026-06-05 |
| CVE-2026-46398 | HAX CMS Missing Secure Flag on Cookie — haxcms-php CWE-614 | - | - | 2026-06-05 |
| CVE-2026-46397 | haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0 — haxcms-php CWE-22 | 6.5 | Medium | 2026-06-05 |
| CVE-2026-46394 | HAX CMS Vulnerable to Command Injection using Git.php — haxcms-php CWE-78 | - | - | 2026-06-05 |
| CVE-2026-46392 | HAX CMS PHP Has a Stored XSS via Case-Sensitivity Mismatch in HTML Upload Validation — haxcms-php CWE-178 | 8.7 | High | 2026-06-05 |
| CVE-2026-46390 | HAX CMS has Unauthenticated Git Access via User-Controlled Key — haxcms-php CWE-639 | - | - | 2026-06-05 |
This page lists every published CVE security advisory associated with haxtheweb. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.