Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q862-gcgq-5m6g | HAXcms createSite SSRF Enables Arbitrary File Read |
Mon, 08 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Haxtheweb
Haxtheweb haxcms-nodejs Haxtheweb haxcms-php |
|
| Vendors & Products |
Haxtheweb
Haxtheweb haxcms-nodejs Haxtheweb haxcms-php |
Fri, 05 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 26.0.0 allows authenticated users to fetch arbitrary internal or local resources and write the responses to a web-accessible directory, enabling arbitrary file read and internal network access. Version 26.0.0 contains a fix. | |
| Title | HAXcms createSite SSRF Enables Arbitrary File Read | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-08T16:08:41.968Z
Reserved: 2026-05-13T19:53:47.923Z
Link: CVE-2026-46393
Updated: 2026-06-08T16:08:16.970Z
Status : Deferred
Published: 2026-06-05T19:16:33.303
Modified: 2026-06-08T17:16:50.713
Link: CVE-2026-46393
No data.
OpenCVE Enrichment
Updated: 2026-06-05T20:45:04Z
Github GHSA