GHSA-2m6p-hm3w-6jm3 · Severity: medium · Ecosystem: npm — HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of the `<video-player>` component. The component allows `javascript:` URIs in the `source` attribute, which are executed when the page is viewed. This enables attackers to execute arbitrary JavaScript in the context of the victim’s browser and access sensitive data such as JWT tokens and more. Version 26.0.0 fixes the issue.
Conclusion & alert: CVE-2026-46496 is rated Moderate Risk (42.1/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.23%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.23% | +0.18% |
| 2 | 2026-06-11 | 0.05% | 0.05% | +0.00% |
| 3 | 2026-06-06 | — | 0.05% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 4.0 | CRITICAL |
|
— | — | [email protected] |
GHSA-2m6p-hm3w-6jm3 · Severity: medium · Ecosystem: npm — HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||