CVE-2026-48527
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedHAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by injecting an event handler attribute without whitespace before the attribute name. @haxtheweb/haxcms-nodejs 26.0.1 and haxcms-php 26.0.2 patch the issue.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceHAX CMS versions up to 26.0.0 contain a stored XSS vulnerability in the /system/api/saveNode API endpoint. Authenticated users with page edit permissions can bypass the HTML sanitizer by injecting event handler attributes (e.g., onclick, onerror) without preceding whitespace, allowing execution of arbitrary JavaScript in the context of other users viewing the compromised content.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- Low
- User interaction
- Required
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify HAX CMS installationLocate the HAX CMS installation directory. For Node.js deployments, check for package.json containing haxcms or haxcms-nodejs. For PHP deployments, look for the haxcms PHP application files.Affected if HAX CMS is present and the installed version is 26.0.0 or earlier based on version comparison
-
Determine installed versionFor Node.js: examine package.json or run npm list haxcms-nodejs. For PHP: check the version file or composer.json if available. Compare the version number to the affected range (up to 26.0.0).Affected if The installed version is 26.0.0 or any version prior to 26.0.1 (nodejs) or 26.0.2 (php)
-
Verify saveNode API endpoint existsConfirm the /system/api/saveNode endpoint is present in the installation by checking the API routing configuration or attempting a request if authorized.Affected if The saveNode endpoint is accessible and accepts POST requests for content saving
-
Confirm HTML sanitizer is in useReview the saveNode endpoint code or configuration to verify the HTML sanitizer module is enabled. This is typically the default but should be confirmed.Affected if The HTML sanitizer is enabled (which is the default configuration)
-
Check user permission configurationReview the user roles and permissions configuration to determine if any users beyond trusted administrators have page edit permissions.Affected if There are authenticated users with page edit permissions beyond trusted administrators
A user is affected if HAX CMS version 26.0.0 or earlier is installed, the saveNode endpoint is accessible, and there are users with page edit permissions who could inject the XSS payload.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedUpgrade to haxcms-php 26.0.2 or @haxtheweb/haxcms-nodejs 26.0.1 or later. In the interim, restrict page edit permissions to only highly trusted users and monitor for suspicious content.
@haxtheweb/haxcms-nodejs 26.0.1 (Node.js) or haxcms-php 26.0.2 (PHP)
- Identify the HAX CMS backend in use (PHP or Node.js)
- If using Node.js backend: upgrade @haxtheweb/haxcms-nodejs to version 26.0.1 or later
- If using PHP backend: upgrade haxcms-php to version 26.0.2 or later
- Verify the upgrade was successful by testing the /system/api/saveNode endpoint with the previously exploited payload to confirm sanitization is working properly
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation2.0 h
- Implementation1.0 h
- Testing4.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $2,464.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-48527 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-48527 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data