HAX CMS Backend Lacks Comprehensive Authorization Checks
Published Jul 26, 2025
8.3
HIGHCVSS 3.1
EPSS 0.50%
Description
HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below of haxcms-php, API endpoints do not perform authorization checks when interacting with a resource. Both the JS and PHP versions of the CMS do not verify that a user has permission to interact with a resource before performing a given operation. The API endpoints within the HAX CMS application check if a user is authenticated, but don't check for authorization before performing an operation. This is fixed in versions 11.0.14 of haxcms-nodejs and 11.0.9 of haxcms-php.
Affected products
-
- Version < 11.0.14StatusaffectedConstraints-
- Version
- < 11.0.14
- < 11.0.9
No data.
No Red Hat product state for this CVE.
@haxtheweb/haxcms-nodejs
npm
Introduced 0 Fixed 11.0.14elmsln/haxcms
Packagist
Introduced 0 Fixed 11.0.14
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @haxtheweb/haxcms-nodejs | 0 | 11.0.14 |
| Packagist | elmsln/haxcms | 0 | 11.0.14 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jul 28, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.50% (0.00500) | 40.58th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.45% (0.00450) | 35.56th | v5 (v2026.06.15) |
| Jul 26, 2025 | 0.03% (0.00034) | 8.24th | v4 (v2025.03.14) |
References (5)
- https://github.com/advisories/GHSA-9jr9-8ff3-m894 Advisory
- https://github.com/haxtheweb/haxcms-nodejs/commit/5826e9b7f3d8c7c7635411768b86b199fad36969 x_refsource_MISCPatch
- https://github.com/haxtheweb/haxcms-php/commit/24d30222481ada037597c4d7c0a51a1ef7af6cfd x_refsource_MISCPatch
- https://github.com/haxtheweb/issues/security/advisories/GHSA-9jr9-8ff3-m894 exploitx_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-54378
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-9jr9-8ff3-m894 | Advisory | |
| https://github.com/haxtheweb/haxcms-nodejs/commit/5826e9b7f3d8c7c7635411768b86b199fad36969 | x_refsource_MISCPatch | |
| https://github.com/haxtheweb/haxcms-php/commit/24d30222481ada037597c4d7c0a51a1ef7af6cfd | x_refsource_MISCPatch | |
| https://github.com/haxtheweb/issues/security/advisories/GHSA-9jr9-8ff3-m894 | exploitx_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-54378 |
Change history (0)
No recorded changes yet.