CVE-2026-22704 | HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover
Exp
HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.
Conclusion & alert: CVE-2026-22704 is rated Exploit Available (54.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.08%).Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2026-22704
Exploit prediction scoring system (EPSS) score for CVE-2026-22704
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).