PT-2026-47040 · Hax Cms · Hax Cms

CVE-2026-46400

·

Published

2026-06-05

·

Updated

2026-06-06

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions HAX CMS versions 11.0.6 through 24.x
Description The file upload functionality in HAXCMS PHP validates file extensions using a regex pattern but fails to verify the actual file content or MIME type (Multipurpose Internet Mail Extensions, a standard that indicates the nature and format of a document). This allows the upload of malicious files, such as PHP webshells, disguised as legitimate images, which can lead to remote code execution.
Recommendations Update to version 25.0.0.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46400

Affected Products

Hax Cms