CVEFinder.io

CVE-2026-46357

🔶 medium
🔍 Scan for this CVE
Summary

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS application crashes when an authenticated attacker sends a specially crafted site creation request to the createSite endpoint. A single request is sufficient to take the entire application offline, requiring a manual server restart to restore service. Version 26.0.0 fixes the issue.

CVSS Score
6.5
Medium
EPSS Score
-
Published Date
2026-06-05
First Seen: 2026-06-06
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 47.8% of all 325,576 vulnerabilities in our database.

#169,855
Below average severity
Severity Percentile
Last Modified 2026-06-05
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE IDs (Weakness Types)

📦 Affected Products 0

No affected products information available

🔗 References 1