{"api_version":"v1","generated_at":"2026-10-07T09:25:00+00:00","product":{"cve_count":16,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-haxtheweb-issues-fac3591856f6","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/issues","name":"issues","next_cursor":null,"observations":[{"affected":"< 26.0.0","affected_versions_present":true,"cve_id":"CVE-2026-46401","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46401","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-08T19:27:53.316Z","patch_url":"","primary_source":"","published":"2026-06-05T19:18:05.286Z"},{"affected":">= 11.0.6, < 25.0.0","affected_versions_present":true,"cve_id":"CVE-2026-22704","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22704","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-13T15:09:03.814Z","patch_url":"https://github.com/haxtheweb/haxcms-nodejs/commit/317a8ae29f88be389f7cfeffaef416957122d97e","primary_source":"","published":"2026-01-10T06:22:45.076Z"},{"affected":"< 11.0.14","affected_versions_present":true,"cve_id":"CVE-2025-54378","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54378","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-07-28T19:01:27.428Z","patch_url":"https://github.com/haxtheweb/haxcms-nodejs/commit/5826e9b7f3d8c7c7635411768b86b199fad36969","primary_source":"","published":"2025-07-26T03:27:34.305Z"},{"affected":"< 11.0.13; < 11.0.8","affected_versions_present":true,"cve_id":"CVE-2025-54139","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54139","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-07-23T14:53:40.521Z","patch_url":"https://github.com/haxtheweb/haxcms-nodejs/commit/777f9a7ff9675a160496f350d766df1f1f9b9b99","primary_source":"","published":"2025-07-22T23:24:13.334Z"},{"affected":"< 11.0.10","affected_versions_present":true,"cve_id":"CVE-2025-54137","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54137","fixed":"11.0.10.","last_modified":"2025-07-23T18:27:54.073Z","patch_url":"https://github.com/haxtheweb/haxcms-nodejs/commit/6dc2441c876350ca6fe9fbaecb058d92ef442869","primary_source":"","published":"2025-07-22T21:34:20.201Z"},{"affected":"< 11.0.9","affected_versions_present":true,"cve_id":"CVE-2025-54134","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54134","fixed":"11.0.9.","last_modified":"2025-07-23T18:30:23.112Z","patch_url":"https://github.com/haxtheweb/haxcms-nodejs/commit/e9773d1996233f9bafb06832b8220ec2a98bab34","primary_source":"","published":"2025-07-21T20:58:35.724Z"},{"affected":"< 11.0.5","affected_versions_present":true,"cve_id":"CVE-2025-54129","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54129","fixed":"11.0.5.","last_modified":"2025-07-22T20:44:14.038Z","patch_url":"https://github.com/haxtheweb/issues/security/advisories/GHSA-wh3h-vfcv-m5g5","primary_source":"","published":"2025-07-21T20:53:26.575Z"},{"affected":"< 11.0.8","affected_versions_present":true,"cve_id":"CVE-2025-54128","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54128","fixed":"11.0.8.","last_modified":"2025-07-22T20:43:50.054Z","patch_url":"https://github.com/haxtheweb/haxcms-nodejs/commit/ddb9351c6d6418008d4084a5b17fd6d611bc4e30","primary_source":"","published":"2025-07-21T20:46:31.660Z"},{"affected":"< 11.0.7","affected_versions_present":true,"cve_id":"CVE-2025-54127","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54127","fixed":"11.0.7.","last_modified":"2025-07-22T19:56:43.124Z","patch_url":"https://github.com/haxtheweb/issues/security/advisories/GHSA-f38f-jvqj-mfg6","primary_source":"","published":"2025-07-21T20:36:43.580Z"},{"affected":"< 11.0.6","affected_versions_present":true,"cve_id":"CVE-2025-53642","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-53642","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-07-14T14:17:55.724Z","patch_url":"","primary_source":"","published":"2025-07-11T17:33:05.861Z"},{"affected":"< 11.0.3","affected_versions_present":true,"cve_id":"CVE-2025-49141","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49141","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-10T15:29:29.971Z","patch_url":"https://github.com/haxtheweb/haxcms-nodejs/commit/5131fea6b6be611db76a618f89bd2e164752e9b3","primary_source":"","published":"2025-06-09T21:11:08.889Z"},{"affected":"< 11.0.0","affected_versions_present":true,"cve_id":"CVE-2025-49139","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49139","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-10T15:29:40.105Z","patch_url":"https://github.com/haxtheweb/haxcms-nodejs/commit/5368eb9b278ca47cd9a83b8d3e6216375615b8f5","primary_source":"","published":"2025-06-09T21:08:44.391Z"},{"affected":"< 11.0.0","affected_versions_present":true,"cve_id":"CVE-2025-49138","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49138","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-06-10T15:29:50.231Z","patch_url":"","primary_source":"","published":"2025-06-09T21:05:23.245Z"},{"affected":"< 11.0.0","affected_versions_present":true,"cve_id":"CVE-2025-49137","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49137","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-10T15:30:09.073Z","patch_url":"https://github.com/haxtheweb/haxcms-php/commit/0dd3e98fe2fadd0793b667d4af2aac230980e0f8","primary_source":"","published":"2025-06-09T21:00:15.808Z"},{"affected":"<= 10.0.2","affected_versions_present":true,"cve_id":"CVE-2025-48996","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48996","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-06-03T02:04:15.413Z","patch_url":"","primary_source":"","published":"2025-06-02T19:24:44.860Z"},{"affected":">= 9.0.0, < 10.0.3","affected_versions_present":true,"cve_id":"CVE-2025-32028","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32028","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-08T20:00:56.916Z","patch_url":"","primary_source":"","published":"2025-04-08T16:06:33.976Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"haxtheweb"}}
