« Back to list

Maxsite

Maxsite CMS: vulnerabilities and CVEs

Maxsite CMS has 16 published vulnerabilities, 14 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.

CVEs16
Last 12 months14
Critical5
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-87930Critical (9.2)0.61%—Sep 9, 2026
MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded…
CVE-2026-87929Critical (9.3)0.53%—Sep 9, 2026
MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session…
CVE-2026-87928Medium (5.1)0.30%—Sep 9, 2026
MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious…
CVE-2026-87927High (8.8)0.59%—Sep 9, 2026
MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded…
CVE-2026-70554Critical (9.3)1.2%—Aug 4, 2026
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to…
CVE-2026-70553Critical (9.3)1.3%—Aug 4, 2026
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install…
CVE-2026-70552Critical (9.3)0.83%—Aug 4, 2026
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and…
CVE-2026-37700Medium (4.1)0.32%—Jun 3, 2026
Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page
CVE-2026-7016Low (1.9)0.38%—Apr 26, 2026
A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote…
CVE-2026-7015Low (1.9)0.38%—Apr 26, 2026
A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross…
CVE-2026-7014Low (1.9)0.38%—Apr 26, 2026
A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may…
CVE-2026-7013Low (1.9)0.38%—Apr 26, 2026
A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from…
CVE-2026-7012Low (1.9)0.38%—Apr 26, 2026
A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be…
CVE-2026-7011Low (1.9)0.38%—Apr 26, 2026
A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the…
CVE-2023-36291Medium (6.1)0.48%—Jul 3, 2023
Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.
CVE-2021-35265Medium (6.1)3.4%—Aug 3, 2021
A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1005 Data from Local System1
  3. T1059 Command and Scripting Interpreter1
  4. T1078 Valid Accounts1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Maxsite