btopro
13 exploits
Active since Jun 2025
haxtheweb/haxcms-php uses insecure method for generating salt
CVSS 7.5
HAX CMS NodeJS < 11.0.9 - Authenticated Denial of Service via Missing URL Parameters
CVSS 6.5
HAX open-apis <10.0.2 - Info Disclosure
CVSS 5.3
PSU Haxcms-nodejs < 11.0.0 - Basic XSS
CVSS 8.5
HAX CMS PHP < 11.0.0 - Website Block Credential Phishing
CVSS 5.3
PSU Haxcms-nodejs < 11.0.3 - OS Command Injection
CVSS 8.5
haxcms-nodejs < 11.0.8 - Cross-Site Scripting via Disabled Content Security Policy
CVSS 6.1
HAX CMS NodeJS <11.0.9 - Info Disclosure
CVSS 7.3
HAX CMS NodeJS and PHP - Clickjacking UI Redressing
CVSS 4.3
HAX CMS NodeJS and PHP - Clickjacking UI Redressing
CVSS 4.3
PSU Haxcms-nodejs < 11.0.14 - Missing Authorization
CVSS 8.3
PSU Haxcms-nodejs < 11.0.14 - Missing Authorization
CVSS 8.3
haxcms-nodejs 11.0.6-24.9.9 - Stored Cross-Site Scripting
CVSS 8.0