VYPR
Unrated severityNVD Advisory· Published Jul 11, 2025· Updated Jul 14, 2025

haxcms-nodejs and haxcms-php Improperly Terminate Sessions

CVE-2025-53642

Description

haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.

Affected products

2
  • HAX CMS/HAXcmsllm-fuzzy
    Range: <11.0.6
  • haxtheweb/issuesv5
    Range: < 11.0.6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.