CVE-2026-48527 is a vulnerability tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed May 29, 2026; most recent activity May 29, 2026.
CVE-2026-48527 is a stored cross-site scripting (XSS) vulnerability in HAX CMS, affecting versions up to 26.0.0. The vulnerability exists in the `/system/api/saveNode` endpoint, where authenticated users with page…