@haxtheweb/haxcms-nodejs
HAXcms single and multisite nodejs server, api, and administration
Security Advisories for @haxtheweb/haxcms-nodejs in npm
High
about 17 hours ago
HaxCMS has a stored Cross-Site Scripting (XSS) bypass in its saveNode endpoint
npm
@haxtheweb/haxcms-nodejs
Moderate
10 days ago
HAX CMS: Denial of Service using Malicious Import Request
npm
@haxtheweb/haxcms-nodejs
High
11 days ago
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
npm
@haxtheweb/haxcms-nodejs
High
11 days ago
Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover
npm
@haxtheweb/iframe-loader, @haxtheweb/video-player, @haxtheweb/haxcms-nodejs
Critical
11 days ago
HAXcms: Private Key Disclosure via Broken HMAC Implementation
npm
@haxtheweb/haxcms-nodejs
Moderate
11 days ago
HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
npm
@haxtheweb/video-player, @haxtheweb/haxcms-nodejs
High
5 months ago
HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover
npm
@haxtheweb/haxcms-nodejs
High
10 months ago
HAX CMS API Lacks Authorization Checks
packagist, npm
elmsln/haxcms, @haxtheweb/haxcms-nodejs
Moderate
10 months ago
HAX CMS application pages vulnerable to clickjacking
packagist, npm
elmsln/haxcms, @haxtheweb/haxcms-nodejs
High
10 months ago
NodeJS version of the HAX CMS application is distributed with Default Secrets
npm
@haxtheweb/haxcms-nodejs
High
10 months ago
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
npm
@haxtheweb/haxcms-nodejs
High
10 months ago
NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting
npm
@haxtheweb/haxcms-nodejs
Critical
10 months ago
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
npm
@haxtheweb/haxcms-nodejs
Moderate
12 months ago
@haxtheweb/haxcms-nodejs Iframe Phishing vulnerability
npm
@haxtheweb/haxcms-nodejs