CVE Database
/

CVE-2026-35185

Back to search

CVE-2026-35185

Published: Apr 6, 2026

Modified: Apr 7, 2026

PUBLISHED

Description

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client IP addresses, and server configuration details. This allows any unauthenticated user to monitor real-time user interactions and gather internal infrastructure information. This vulnerability is fixed in 25.0.0.

VendorProductVersions

haxtheweb

HAXiam

affected
< 25.0.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2026-35185 - Security Vulnerability | QwikSec