Vulnerabilities/

Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover

Severity:
High

Description

A stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of <iframe> elements.

The application allows javascript: URIs in the src attribute, which are executed when a malicious page is viewed.

Recommendation

Update the @haxtheweb/iframe-loader package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@haxtheweb/iframe-loader
Anything's wrong? Let us know Last updated on May 19, 2026