VYPR
Vendor

MaxSite CMS

Products
3
CVEs
9
Across products
11
Status
Private

Products

3

Recent CVEs

9
  • CVE-2022-25411CriFeb 28, 2022
    risk 0.64cvss 9.8epss 0.03

    A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-25412HigFeb 28, 2022
    risk 0.53cvss 8.1epss 0.01

    Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.

  • CVE-2026-3395HigMar 1, 2026
    risk 0.41cvss 7.3epss 0.02

    A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to…

  • CVE-2023-36291MedJul 3, 2023
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.

  • CVE-2021-35265MedAug 3, 2021
    risk 0.40cvss 6.1epss 0.03

    A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.

  • CVE-2022-25413MedFeb 28, 2022
    risk 0.35cvss 5.4epss 0.00

    Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.

  • CVE-2022-25410MedFeb 28, 2022
    risk 0.35cvss 5.4epss 0.00

    Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.

  • CVE-2026-7016LowApr 26, 2026
    risk 0.09cvss 2.4epss 0.00

    A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2026-7014LowApr 26, 2026
    risk 0.09cvss 2.4epss 0.00

    A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may be initiated remotely. The exploit has been published and…