Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.61%—Maxsite CMSAI9/9/20269/9/2026
MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if…
AplazadaCrítica (9.3)0.53%—Maxsite CMSAI9/9/202614/9/2026
MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with administrator privileges by computing an…
AplazadaAlta (8.8)0.59%—Maxsite CMSAI9/9/20269/9/2026
MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler…
AplazadaMedia (5.1)0.30%—Maxsite CMSAI9/9/202618/9/2026
MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious scripts to the uploads/_pages/ directory, which executes in visitors' browsers when the file is…
AplazadaCrítica (9.3)1.2%—Maxsite CMSAI4/8/202631/8/2026
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP…
AplazadaCrítica (9.3)1.3%—Maxsite CMSAI4/8/202631/8/2026
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing…
AplazadaCrítica (9.3)0.83%—Maxsite CMSAI4/8/202631/8/2026
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can…
AplazadaMedia (4.1)0.32%—Maxsite CMSAI3/6/202622/7/2026
Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page
AplazadaBaja (1.9)0.38%—Maxsite CMSAI26/4/202617/6/2026
A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used. Upgrading…
AplazadaBaja (1.9)0.38%—Maxsite CMSAI26/4/202617/6/2026
A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and…
AplazadaBaja (1.9)0.38%—Maxsite CMSAI26/4/202617/6/2026
A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 109.4…
AplazadaBaja (1.9)0.38%—Maxsite CMSAI26/4/202617/6/2026
A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed…
AplazadaBaja (1.9)0.38%—Maxsite CMSAI26/4/202617/6/2026
A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 109.4 is able to…
AplazadaBaja (1.9)0.38%—Maxsite CMSAI26/4/202617/6/2026
A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lead to cross site scripting. It is possible to launch the attack…
AnalizadaMedia (5.5)2.5%—Max-3000 Maxsite CMS1/3/202617/6/2026
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit…
AnalizadaBaja (2.1)0.40%—Max-3000 Maxsite CMS28/10/202517/6/2026
A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricted upload. The attack can be executed remotely. The exploit has been…
AnalizadaBaja (2.1)0.40%—Max-3000 Maxsite CMS28/10/202517/6/2026
A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the argument X-Requested-FileName/X-Requested-FileUpDir results in…
ModificadaMedia (6.1)0.48%—Maxsite CMS3/7/202317/6/2026
Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.
ModificadaMedia (5.4)0.49%—Max-3000 Maxsite CMS28/2/202217/6/2026
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
ModificadaAlta (8.1)1.1%—Max-3000 Maxsite CMS28/2/202217/6/2026
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.
ModificadaCrítica (9.8)3.0%—Max-3000 Maxsite CMS28/2/202217/6/2026
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (5.4)0.49%—Max-3000 Maxsite CMS28/2/202217/6/2026
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.
ModificadaCrítica (9.8)3.5%—Max-3000 Maxsite CMS10/12/202117/6/2026
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
ModificadaMedia (6.1)3.4%—Maxsite CMS3/8/202117/6/2026
A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.