Max-3000
Max-3000 Maxsite CMS: vulnerabilidades y CVE
Max-3000 Maxsite CMS tiene 8 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses3
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-3395 | Media (5.5) | 2.5% | — | 1 mar 2026 | A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing… |
| CVE-2025-12347 | Baja (2.1) | 0.40% | — | 28 oct 2025 | A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument… |
| CVE-2025-12346 | Baja (2.1) | 0.40% | — | 28 oct 2025 | A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler.… |
| CVE-2022-25413 | Media (5.4) | 0.49% | — | 28 feb 2022 | Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3. |
| CVE-2022-25412 | Alta (8.1) | 1.1% | — | 28 feb 2022 | Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters. |
| CVE-2022-25411 | Crítica (9.8) | 3.0% | — | 28 feb 2022 | A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file. |
| CVE-2022-25410 | Media (5.4) | 0.49% | — | 28 feb 2022 | Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files. |
| CVE-2021-27983 | Crítica (9.8) | 3.5% | — | 10 dic 2021 | Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page. |