Maxsite
Products
6- 9 CVEs
- 7 CVEs
- 7 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
19| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-70554 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers… | ||
| CVE-2026-70553 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply… | ||
| CVE-2026-70552 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php… | ||
| CVE-2022-25411 | Cri | 0.64 | 9.8 | 0.03 | Feb 28, 2022 | A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2021-27983 | Cri | 0.64 | 9.8 | 0.03 | Dec 10, 2021 | Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page. | ||
| CVE-2022-25412 | Hig | 0.53 | 8.1 | 0.01 | Feb 28, 2022 | Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters. | ||
| CVE-2025-12347 | Med | 0.41 | 6.3 | 0.00 | Oct 28, 2025 | A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricted upload. The attack can be… | ||
| CVE-2025-12346 | Med | 0.41 | 6.3 | 0.00 | Oct 28, 2025 | A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the argument… | ||
| CVE-2023-36291 | Med | 0.40 | 6.1 | 0.00 | Jul 3, 2023 | Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file. | ||
| CVE-2022-25413 | Med | 0.35 | 5.4 | 0.00 | Feb 28, 2022 | Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3. | ||
| CVE-2022-25410 | Med | 0.35 | 5.4 | 0.00 | Feb 28, 2022 | Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files. | ||
| CVE-2026-37700 | Med | 0.27 | 4.1 | 0.00 | Jun 3, 2026 | Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page | ||
| CVE-2026-7015 | Low | 0.09 | 2.4 | 0.00 | Apr 26, 2026 | A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be launched remotely. The… | ||
| CVE-2026-7013 | Low | 0.09 | 2.4 | 0.00 | Apr 26, 2026 | A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. The attack can be initiated… | ||
| CVE-2026-7012 | Low | 0.09 | 2.4 | 0.00 | Apr 26, 2026 | A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be… | ||
| CVE-2026-7011 | Low | 0.09 | 2.4 | 0.00 | Apr 26, 2026 | A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lead to cross site scripting. It… | ||
| CVE-2008-6446 | 0.03 | — | 0.02 | Mar 9, 2009 | Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrary PHP code into the guestbook via the message parameter. | |||
| CVE-2008-2487 | 0.03 | — | 0.01 | May 28, 2008 | SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action. | |||
| CVE-2021-35265 | Med | 0.00 | 6.1 | 0.03 | Aug 3, 2021 | A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page. |
- risk 0.64cvss 9.8epss 0.01
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers…
- risk 0.64cvss 9.8epss 0.01
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply…
- risk 0.64cvss 9.8epss 0.01
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php…
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
- risk 0.53cvss 8.1epss 0.01
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.
- risk 0.41cvss 6.3epss 0.00
A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricted upload. The attack can be…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the argument…
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.
- risk 0.35cvss 5.4epss 0.00
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
- risk 0.35cvss 5.4epss 0.00
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.
- risk 0.27cvss 4.1epss 0.00
Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page
- risk 0.09cvss 2.4epss 0.00
A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be launched remotely. The…
- risk 0.09cvss 2.4epss 0.00
A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. The attack can be initiated…
- risk 0.09cvss 2.4epss 0.00
A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be…
- risk 0.09cvss 2.4epss 0.00
A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lead to cross site scripting. It…
- CVE-2008-6446Mar 9, 2009risk 0.03cvss —epss 0.02
Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrary PHP code into the guestbook via the message parameter.
- CVE-2008-2487May 28, 2008risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action.
- risk 0.00cvss 6.1epss 0.03
A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.