Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22265 | NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting |
Github GHSA |
GHSA-59g8-h59f-8hjp | NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting |
Wed, 30 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Psu
Psu haxcms-nodejs |
|
| CPEs | cpe:2.3:a:psu:haxcms-nodejs:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Psu
Psu haxcms-nodejs |
|
| Metrics |
cvssV3_1
|
Tue, 22 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Jul 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Haxtheweb
Haxtheweb haxcms-nodejs |
|
| Vendors & Products |
Haxtheweb
Haxtheweb haxcms-nodejs |
Mon, 21 Jul 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks. The contentSecurityPolicy value is explicitly disabled in the application's Helmet configuration in app.js. This is fixed in version 11.0.8. | |
| Title | HAX CMS NodeJs's Disabled Content Security Policy Enables Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-22T20:43:50.054Z
Reserved: 2025-07-16T23:53:40.509Z
Link: CVE-2025-54128
Updated: 2025-07-22T20:43:46.384Z
Status : Analyzed
Published: 2025-07-21T21:15:26.553
Modified: 2025-07-30T17:04:15.720
Link: CVE-2025-54128
No data.
OpenCVE Enrichment
Updated: 2025-07-22T10:01:11Z
EUVD
Github GHSA