Cross-site Scripting (XSS)Weakness · CWE-79

CVE-2026-48527

HIGH · 8.7 CVSS v3.1 Published 2026-05-29
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
91/100
Remediation priority · Urgent
Remotely reachable

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by injecting an event handler attribute without whitespace before the attribute name. @haxtheweb/haxcms-nodejs 26.0.1 and haxcms-php 26.0.2 patch the issue.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

HAX CMS versions up to 26.0.0 contain a stored XSS vulnerability in the /system/api/saveNode API endpoint. Authenticated users with page edit permissions can bypass the HTML sanitizer by injecting event handler attributes (e.g., onclick, onerror) without preceding whitespace, allowing execution of arbitrary JavaScript in the context of other users viewing the compromised content.

MitigationUpgrade to haxcms-php 26.0.2 or @haxtheweb/haxcms-nodejs 26.0.1 or later. In the interim, restrict page edit permissions to only highly trusted users and monitor for suspicious content.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
Low
User interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Identify HAX CMS installation
    Locate the HAX CMS installation directory. For Node.js deployments, check for package.json containing haxcms or haxcms-nodejs. For PHP deployments, look for the haxcms PHP application files.
    Affected if HAX CMS is present and the installed version is 26.0.0 or earlier based on version comparison
  2. Determine installed version
    For Node.js: examine package.json or run npm list haxcms-nodejs. For PHP: check the version file or composer.json if available. Compare the version number to the affected range (up to 26.0.0).
    Affected if The installed version is 26.0.0 or any version prior to 26.0.1 (nodejs) or 26.0.2 (php)
  3. Verify saveNode API endpoint exists
    Confirm the /system/api/saveNode endpoint is present in the installation by checking the API routing configuration or attempting a request if authorized.
    Affected if The saveNode endpoint is accessible and accepts POST requests for content saving
  4. Confirm HTML sanitizer is in use
    Review the saveNode endpoint code or configuration to verify the HTML sanitizer module is enabled. This is typically the default but should be confirmed.
    Affected if The HTML sanitizer is enabled (which is the default configuration)
  5. Check user permission configuration
    Review the user roles and permissions configuration to determine if any users beyond trusted administrators have page edit permissions.
    Affected if There are authenticated users with page edit permissions beyond trusted administrators

A user is affected if HAX CMS version 26.0.0 or earlier is installed, the saveNode endpoint is accessible, and there are users with page edit permissions who could inject the XSS payload.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Upgrade to haxcms-php 26.0.2 or @haxtheweb/haxcms-nodejs 26.0.1 or later. In the interim, restrict page edit permissions to only highly trusted users and monitor for suspicious content.

Recommended fix High confidence

@haxtheweb/haxcms-nodejs 26.0.1 (Node.js) or haxcms-php 26.0.2 (PHP)

  1. Identify the HAX CMS backend in use (PHP or Node.js)
  2. If using Node.js backend: upgrade @haxtheweb/haxcms-nodejs to version 26.0.1 or later
  3. If using PHP backend: upgrade haxcms-php to version 26.0.2 or later
  4. Verify the upgrade was successful by testing the /system/api/saveNode endpoint with the previously exploited payload to confirm sanitization is working properly

Generated from the published advisory — verify against the referenced sources before acting.

Have this fixed Scoped from the published advisory
  • Consultation2.0 h
  • Implementation1.0 h
  • Testing4.0 h
  • Review / QA2.0 h
9.0 hours of engineering $1,540
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $2,464.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-48527 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-48527 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data