Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

haxtheweb — Vulnerabilities & Security Advisories 33

Browse all 33 CVE security advisories affecting haxtheweb. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Haxtheweb primarily develops web applications and APIs for enterprise clients, with a core focus on custom business solutions. Historically, the organization has been associated with multiple remote code execution, cross-site scripting, and privilege escalation vulnerabilities across its products. Security assessments reveal consistent flaws in input validation and authentication mechanisms. While no major public breaches have been directly attributed to haxtheweb, its cumulative 16 CVEs indicate systemic security weaknesses in development practices. The organization's codebase frequently demonstrates inadequate sanitization of user inputs and misconfigured access controls, creating persistent exposure vectors for attackers.

Found 7 results / 33Clear Filters
High2026-06-13
haxcms-php/install.php at 8b8845b16e521a326929471e16903f60c6638e8f · haxtheweb/haxcms-php · GitHub
MediumGHSA-6434-8trh-w65c2026-06-13
Unauthenticated Git Access via User-Controlled Key · Advisory · haxtheweb/issues · GitHub
HighCVE-2024-483972026-06-13
haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0 · Advisory · haxtheweb/issues · GitHub
High2026-06-13
Stored XSS via Case-Sensitivity Mismatch in HTML Upload Validation · Advisory · haxtheweb/issues · GitHub
CriticalCVE-2024-49112026-06-13
Mass Token Exfiltration and Cross-Tenant Hijack · Advisory · haxtheweb/issues · GitHub
High2026-05-29
Stored Cross-Site Scripting (XSS) bypass in saveNode endpoint · Advisory · haxtheweb/issues · GitHub
HighCVE-2026-351852026-04-07
Public /server-status endpoint exposes authentication tokens, user activity, and client IP addresse · Advisory · haxthew
HighCVE-2015-51732025-07-30
Lack of Authorization Checks · Advisory · haxtheweb/issues · GitHub
UnknownGHSA-9jr9-8ff2025-07-26
haxcms-nodejs/src/routes/listFiles.js at main · haxtheweb/haxcms-nodejs · GitHub
HighGHSA-2vc4-3hx2025-06-11
https://github.com/haxtheweb/issues/security/advisories/GHSA-2vc4-3hx… · haxtheweb/haxcms-php@0dd3e98 · GitHub
HighCVE-2023-491382025-06-11
Local File Inclusion via saveOutline API Location Parameter · Advisory · haxtheweb/issues · GitHub
High2025-06-11
HaxCMS-PHP Command Injection Vulnerability · Advisory · haxtheweb/issues · GitHub
MediumCVE-2025-489962025-06-04
Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint · Advisory · haxtheweb/issues · Git

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with haxtheweb. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.