CVE-2026-46496 - HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
CVE ID :CVE-2026-46496 Published : June 5, 2026, 7:16 p.m. | 1 hour, 58 minutes ago Description :HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of the ``...