Vulnerability library
Security checkJune 09, 2026

Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of <iframe> elements.

The application allows javascript: URIs in the src attribute, which are executed when a malicious page is viewed.

Recommendation

Update the @haxtheweb/iframe-loader package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 25.0.0
  • Patched version(s): 26.0.0

References

Could your website be exposed too?

SmartScanner can check your website for Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated June 09, 2026