CVE-2025-53642: Psu Haxcms-Node.js
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
Affected products
Published 2025-07-11. Last modified 2026-06-17.