GHSA-2vc4-3hx7-v7v7 · Severity: high · Ecosystem: composer — Hax CMS Stored Cross-Site Scripting vulnerability
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user input, allowing for the execution of arbitrary JavaScript code. The 'saveNode' and 'saveManifest' endpoints take user input and store it in the JSON schema for the site. This content is then rendered in the generated HAX site. Although the application does not allow users to supply a `script` tag, it does allow the use of other HTML tags to run JavaScript. Version 11.0.0 fixes the issue.
Conclusion & alert: CVE-2025-49137 is rated High Exploit Risk (67.1/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.28%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-05 | 0.05% | 0.28% | +0.22% |
| 2 | 2026-01-13 | 0.03% | 0.05% | +0.02% |
| 3 | 2025-11-21 | — | 0.03% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.5 | 3.1 | HIGH |
|
3.1 | 4.7 | [email protected] |
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
GHSA-2vc4-3hx7-v7v7 · Severity: high · Ecosystem: composer — Hax CMS Stored Cross-Site Scripting vulnerability
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| psu | haxcms-nodejs | < 11.0.0 | cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:* |
| psu | haxcms-php | < 11.0.0 | cpe:2.3:a:psu:haxcms-php:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/haxtheweb/haxcms-php/commit/0dd3e98fe2fadd0793b667d4af2aac230980e0f8 | Patch |
| https://github.com/haxtheweb/issues/security/advisories/GHSA-2vc4-3hx7-v7v7 | Exploit Issue Tracking Third Party Advisory |