A vulnerability classified as critical was found in haxtheweb haxcms up to 11.0.6. This vulnerability affects unknown code of the component Setting Handler. The manipulation leads to insecure default initialization of resource.

This vulnerability was named CVE-2025-54127. The attack can be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.