<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Haxcms — PoC Archive</title><link>https://poc.intelseclab.com/tags/haxcms/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/haxcms/index.xml" rel="self" type="application/rss+xml"/><item><title>HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46395-haxcms-hmac-key-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46395-haxcms-hmac-key-leak/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-46395. Status: PoC. Affects: HAXcms Node.js backend (elmsln/HAXcms, haxcms-nodejs) — src/lib/HAXCMS.js. Tags: haxcms, nodejs, hmac, jwt-forgery, cwe-321, cwe-200, key-disclosure, cms.</description><category>web</category><category>Critical</category><category>haxcms</category><category>nodejs</category><category>hmac</category><category>jwt-forgery</category><category>cwe-321</category><category>cwe-200</category><category>key-disclosure</category><category>cms</category></item><item><title>HAXcms Git.php OS Command Injection (CVE-2026-46394)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46394-haxcms-git-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46394-haxcms-git-command-injection/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-46394. Status: PoC. Affects: HAXcms PHP backend (elmsln/HAXcms) — system/backend/php/lib/Git.php. Tags: haxcms, php, command-injection, cwe-78, git, proc_open, cms.</description><category>web</category><category>High</category><category>haxcms</category><category>php</category><category>command-injection</category><category>cwe-78</category><category>git</category><category>proc_open</category><category>cms</category></item><item><title>@haxtheweb/open-apis Credential Exposure via SSRF in cacheAddress Endpoint (CVE-2026-46391)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46391-haxtheweb-open-apis-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46391-haxtheweb-open-apis-ssrf/</guid><description>High severity — web · CVE-2026-46391 (GHSA-4fg7-f244-3j49). Status: PoC. Affects: @haxtheweb/open-apis (HAXcms/HAX ecosystem web service APIs). Tags: haxtheweb, haxcms, open-apis, ssrf, cwe-918, credential-exposure, cacheaddress.</description><category>web</category><category>High</category><category>haxtheweb</category><category>haxcms</category><category>open-apis</category><category>ssrf</category><category>cwe-918</category><category>credential-exposure</category><category>cacheaddress</category></item></channel></rss>