CVE-2025-53642: Psu Haxcms-Node.js

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.

Affected products

  • Psu Haxcms-Node.js: before 11.0.6 (fixed in 11.0.6)
  • Psu Haxcms-PHP: before 11.0.6 (fixed in 11.0.6)

Published 2025-07-11. Last modified 2026-06-17.