CVE-2025-54134
HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the listFiles and saveFiles endpoints. This vulnerability exists because the application does not properly handle exceptions which occur as a result of changes to user-modifiable URL parameters. This is fixed in version 11.0.9.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.40%
- CWE
- CWE-20, CWE-248, CWE-703
- Published
- 2025-07-21
- Last modified
- 2026-03-12
Affected products
- haxtheweb issues
Weakness type
Related vulnerabilities
- CVE-2026-13745 — Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2026-86768 — Snipe-IT before 8.7.0 Improper Input Validation via API Checkout
- CVE-2025-71417 — PocketMine-MP before 5.32.1 Denial of Service via ResourcePackClientResponsePacket
- CVE-2024-58380 — PocketMine-MP before 5.11.2 Denial of Service via BookEditPacket
- CVE-2023-54393 — PocketMine-MP before 4.20.5 Denial of Service via LoginPacket
- CVE-2023-54392 — PocketMine-MP before 4.22.3 Denial of Service via BlockActorDataPacket
- CVE-2026-74761 — Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId