Package impact

npm npm / @haxtheweb/video-player

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-46396 high 8.0 10d ago Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover
CVE-2026-46496 medium 5.5 10d ago HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft