Headless CMS for managing and publishing hybrid static, web component driven sites.
elmsln/[email protected] has vulnerabilities — update to latest
Update to >= 11.0.0 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2025-49137 | Hax CMS Stored Cross-Site Scripting vulnerability | 11.0.0 |
| medium | CVE-2025-54139 | HAX CMS application pages vulnerable to clickjacking | 11.0.8 |
| high | CVE-2025-54378 | HAX CMS API Lacks Authorization Checks | 11.0.14 |
| medium | CVE-2025-49138 | HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter | 11.0.0 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/composer/elmsln/haxcmsLast updated · 2019-10-03T14:31:58+00:00