Maxsite
by Maxsite
Source repositories
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-70554 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers… | ||
| CVE-2026-70552 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php… | ||
| CVE-2022-25411 | Cri | 0.64 | 9.8 | 0.03 | Feb 28, 2022 | A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2021-27983 | Cri | 0.64 | 9.8 | 0.03 | Dec 10, 2021 | Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page. | ||
| CVE-2025-12347 | Med | 0.41 | 6.3 | 0.00 | Oct 28, 2025 | A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricted upload. The attack can be… | ||
| CVE-2025-12346 | Med | 0.41 | 6.3 | 0.00 | Oct 28, 2025 | A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the argument… | ||
| CVE-2021-35265 | Med | 0.40 | 6.1 | 0.03 | Aug 3, 2021 | A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page. | ||
| CVE-2026-87928 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious scripts to the uploads/_pages/ directory, which executes in… | ||
| CVE-2008-2487 | 0.03 | — | 0.01 | May 28, 2008 | SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action. |
- risk 0.64cvss 9.8epss 0.01
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers…
- risk 0.64cvss 9.8epss 0.01
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php…
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
- risk 0.41cvss 6.3epss 0.00
A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricted upload. The attack can be…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the argument…
- risk 0.40cvss 6.1epss 0.03
A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.
- risk 0.35cvss 5.4epss 0.00
MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious scripts to the uploads/_pages/ directory, which executes in…
- CVE-2008-2487May 28, 2008risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action.