Maxsite
Maxsite CMS: vulnerabilidades y CVE
Maxsite CMS tiene 16 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses14
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-87930 | Crítica (9.2) | 0.61% | — | 9 sept 2026 | MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded… |
| CVE-2026-87929 | Crítica (9.3) | 0.53% | — | 9 sept 2026 | MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session… |
| CVE-2026-87927 | Alta (8.8) | 0.59% | — | 9 sept 2026 | MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded… |
| CVE-2026-87928 | Media (5.1) | 0.30% | — | 9 sept 2026 | MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious… |
| CVE-2026-70554 | Crítica (9.3) | 1.2% | — | 4 ago 2026 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to… |
| CVE-2026-70553 | Crítica (9.3) | 1.3% | — | 4 ago 2026 | MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install… |
| CVE-2026-70552 | Crítica (9.3) | 0.83% | — | 4 ago 2026 | MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and… |
| CVE-2026-37700 | Media (4.1) | 0.32% | — | 3 jun 2026 | Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page |
| CVE-2026-7016 | Baja (1.9) | 0.38% | — | 26 abr 2026 | A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote… |
| CVE-2026-7015 | Baja (1.9) | 0.38% | — | 26 abr 2026 | A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross… |
| CVE-2026-7014 | Baja (1.9) | 0.38% | — | 26 abr 2026 | A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may… |
| CVE-2026-7013 | Baja (1.9) | 0.38% | — | 26 abr 2026 | A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from… |
| CVE-2026-7012 | Baja (1.9) | 0.38% | — | 26 abr 2026 | A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be… |
| CVE-2026-7011 | Baja (1.9) | 0.38% | — | 26 abr 2026 | A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the… |
| CVE-2023-36291 | Media (6.1) | 0.48% | — | 3 jul 2023 | Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file. |
| CVE-2021-35265 | Media (6.1) | 3.4% | — | 3 ago 2021 | A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.