HaxCMS has a stored Cross-Site Scripting (XSS) bypass in its saveNode endpoint (CVE-2026-48527) | HOL Guard CVE