Maxsite
Maxsite CMS: vulnerabilities and CVEs
Maxsite CMS has 16 published vulnerabilities, 14 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.
CVEs16
Last 12 months14
Critical5
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87930 | Critical (9.2) | 0.61% | — | Sep 9, 2026 | MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded… |
| CVE-2026-87929 | Critical (9.3) | 0.53% | — | Sep 9, 2026 | MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session… |
| CVE-2026-87928 | Medium (5.1) | 0.30% | — | Sep 9, 2026 | MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious… |
| CVE-2026-87927 | High (8.8) | 0.59% | — | Sep 9, 2026 | MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded… |
| CVE-2026-70554 | Critical (9.3) | 1.2% | — | Aug 4, 2026 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to… |
| CVE-2026-70553 | Critical (9.3) | 1.3% | — | Aug 4, 2026 | MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install… |
| CVE-2026-70552 | Critical (9.3) | 0.83% | — | Aug 4, 2026 | MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and… |
| CVE-2026-37700 | Medium (4.1) | 0.32% | — | Jun 3, 2026 | Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page |
| CVE-2026-7016 | Low (1.9) | 0.38% | — | Apr 26, 2026 | A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote… |
| CVE-2026-7015 | Low (1.9) | 0.38% | — | Apr 26, 2026 | A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross… |
| CVE-2026-7014 | Low (1.9) | 0.38% | — | Apr 26, 2026 | A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may… |
| CVE-2026-7013 | Low (1.9) | 0.38% | — | Apr 26, 2026 | A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from… |
| CVE-2026-7012 | Low (1.9) | 0.38% | — | Apr 26, 2026 | A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be… |
| CVE-2026-7011 | Low (1.9) | 0.38% | — | Apr 26, 2026 | A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the… |
| CVE-2023-36291 | Medium (6.1) | 0.48% | — | Jul 3, 2023 | Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file. |
| CVE-2021-35265 | Medium (6.1) | 3.4% | — | Aug 3, 2021 | A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.