Security: haxtheweb/issues
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unguarded SSRF in createSite build.siteFiles, the sibling path the build.files fix did not reachGHSA-5wp5-hfp3-jc4h published
Aug 14, 2026 by btoproHigh -
haxcms-nodejs: admin account auto-seeded with default credentials admin/admin (CWE-798)GHSA-j9p8-vw68-76ww published
Aug 14, 2026 by btoproCritical -
HAXCMS stored XSS sanitizer bypass via slash-delimited event attributesGHSA-4373-r6wj-chq8 published
Aug 14, 2026 by btoproHigh -
Unauthorized Site ModificationGHSA-qhxx-w7r4-hrhj published
Aug 14, 2026 by btoproHigh -
Stored Cross-Site Scripting (XSS) bypass in saveNode endpointGHSA-g2g8-95qg-v35h published
May 21, 2026 by btoproHigh -
haxtheweb/haxcms-php uses insecure method for generating saltGHSA-xg43-xm47-74cp published
May 14, 2026 by btoproHigh -
Denial of Service using Malicious Import RequestGHSA-9r33-xhw8-4qqp published
May 13, 2026 by btoproModerate -
Credential Theft via Server-Side Request Forgery (SSRF) in open-apisGHSA-4fg7-f244-3j49 published
May 12, 2026 by btoproHigh -
Stored XSS via Case-Sensitivity Mismatch in HTML Upload ValidationGHSA-hg33-w4j2-95qp published
May 12, 2026 by btoproHigh -
CDN Fallback Server Exposes .git Directory and GitHub CredentialGHSA-f9mm-pqx5-j36f published
May 12, 2026 by btoproHigh