CVE-2026-46396 - HAX CMS has a stored XSS via <iframe> that allows access to sensitive client-side data and account takeover
CVE ID :CVE-2026-46396 Published : June 5, 2026, 7:16 p.m. | 1 hour, 58 minutes ago Description :HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of ``...