VYPR

Maxsite CMS

by Maxsite

Source repositories

CVEs (7)

  • CVE-2026-70552CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php…

  • CVE-2023-36291MedJul 3, 2023
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.

  • CVE-2026-37700MedJun 3, 2026
    risk 0.27cvss 4.1epss 0.00

    Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page

  • CVE-2026-7015LowApr 26, 2026
    risk 0.09cvss 2.4epss 0.00

    A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be launched remotely. The…

  • CVE-2026-7013LowApr 26, 2026
    risk 0.09cvss 2.4epss 0.00

    A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. The attack can be initiated…

  • CVE-2026-7012LowApr 26, 2026
    risk 0.09cvss 2.4epss 0.00

    A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be…

  • CVE-2021-35265MedAug 3, 2021
    risk 0.00cvss 6.1epss 0.03

    A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.