Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-53642


haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.


Published

2025-07-11T18:15:35.123

Last Modified

2025-08-22T16:52:08.603

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-613

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application psu haxcms-nodejs < 11.0.6 Yes
Application psu haxcms-php < 11.0.6 Yes

References