VYPR

Maxsite

by Maxsite

Source repositories

CVEs (7)

  • CVE-2026-70553CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply…

  • CVE-2022-25411CriFeb 28, 2022
    risk 0.64cvss 9.8epss 0.03

    A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-27983CriDec 10, 2021
    risk 0.64cvss 9.8epss 0.03

    Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.

  • CVE-2025-12347MedOct 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricted upload. The attack can be…

  • CVE-2025-12346MedOct 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the argument…

  • CVE-2008-2487May 28, 2008
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action.

  • CVE-2021-35265MedAug 3, 2021
    risk 0.00cvss 6.1epss 0.03

    A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.