Skip to content

CVE-2026-48527

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
May 29, 2026
Last Seen
May 29, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

CVE-2026-48527 is a stored cross-site scripting (XSS) vulnerability in HAX CMS, affecting versions up to 26.0.0. The vulnerability exists in the `/system/api/saveNode` endpoint, where authenticated users with page editing permissions can bypass the HTML sanitizer. This allows them to inject maliciou...

Public Exploits

Checking GitHub for proof-of-concept code…