U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-49137

Change History

New CVE Received from GitHub, Inc. 6/09/2025 5:15:46 PM

Action Type Old Value New Value
Added Description

								
							
							
						
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user input, allowing for the execution of arbitrary JavaScript code. The 'saveNode' and 'saveManifest' endpoints take user input and store it in the JSON schema for the site. This content is then rendered in the generated HAX site. Although the application does not allow users to supply a `script` tag, it does allow the use of other HTML tags to run JavaScript. Version 11.0.0 fixes the issue.
Added CVSS V3.1

								
							
							
						
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Added CWE

								
							
							
						
CWE-79
Added CWE

								
							
							
						
CWE-80
Added CWE

								
							
							
						
CWE-87
Added Reference

								
							
							
						
https://github.com/haxtheweb/haxcms-php/commit/0dd3e98fe2fadd0793b667d4af2aac230980e0f8
Added Reference

								
							
							
						
https://github.com/haxtheweb/issues/security/advisories/GHSA-2vc4-3hx7-v7v7