CVE-2025-54139
published 2025-07-23CVE-2025-54139: HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions…
PriorityP430medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.30%
21.6th percentile
HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all pages within the HAX CMS application do not contain headers to prevent other websites from loading the site within an iframe. This applies to both the CMS and generated sites. An unauthenticated attacker can load the standalone login page or other sensitive functionality within an iframe, performing a UI redressing attack (clickjacking). This can be used to perform social engineering attacks to attempt to coerce users into performing unintended actions within the HAX CMS application. This is fixed in haxcms-nodejs version 11.0.13 and haxcms-php 11.0.8.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| elmsln | haxcms | >= 0 < 11.0.8 | 11.0.8 |
| haxtheweb | haxcms-nodejs | >= 0 < 11.0.13 | 11.0.13 |
| haxtheweb | issues | < 11.0.13 | 11.0.13 |
| haxtheweb | issues | < 11.0.8 | 11.0.8 |
| psu | haxcms-nodejs | >= 11.0.6 < 11.0.13 | 11.0.13 |
| psu | haxcms-php | >= 11.0.0 < 11.0.8 | 11.0.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
HAX CMS application pages vulnerable to clickjacking
osv·2025-07-21
CVE-2025-54139 [MEDIUM] HAX CMS application pages vulnerable to clickjacking
HAX CMS application pages vulnerable to clickjacking
### Summary
All pages within the HAX CMS application do not contain headers to stop other websites from loading the site within an iframe. This applies to both the CMS and generated sites.
### PoC
To replicate this vulnerability, load the target page in an iframe and observe the rendered content.
### Impact
An unauthenticated attacker can load the standalone login page or other sensitive functionality within an iframe, performing a UI redressing attack (Clickjacking). This can be used to perform social engineering attacks to attempt to coerce users into performing unintended actions within the HAX CMS application.
GHSA
HAX CMS application pages vulnerable to clickjacking
ghsa·2025-07-21
CVE-2025-54139 [MEDIUM] CWE-1021 HAX CMS application pages vulnerable to clickjacking
HAX CMS application pages vulnerable to clickjacking
### Summary
All pages within the HAX CMS application do not contain headers to stop other websites from loading the site within an iframe. This applies to both the CMS and generated sites.
### PoC
To replicate this vulnerability, load the target page in an iframe and observe the rendered content.
### Impact
An unauthenticated attacker can load the standalone login page or other sensitive functionality within an iframe, performing a UI redressing attack (Clickjacking). This can be used to perform social engineering attacks to attempt to coerce users into performing unintended actions within the HAX CMS application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/haxtheweb/haxcms-nodejs/commit/777f9a7ff9675a160496f350d766df1f1f9b9b99https://github.com/haxtheweb/haxcms-php/commit/708dc8518928fe307044e67bff8b0f397cfdd606https://github.com/haxtheweb/issues/security/advisories/GHSA-54vw-f4xf-f92jhttps://github.com/haxtheweb/issues/security/advisories/GHSA-54vw-f4xf-f92j
2025-07-23
Published