CVE-2026-3395
- EPSS 0.05%
- Veröffentlicht 01.03.2026 14:16:05
- Zuletzt bearbeitet 05.03.2026 01:24:40
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code...
CVE-2025-12347
- EPSS 0.03%
- Veröffentlicht 28.10.2025 02:02:13
- Zuletzt bearbeitet 06.11.2025 20:04:08
A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricte...
CVE-2025-12346
- EPSS 0.03%
- Veröffentlicht 28.10.2025 02:02:09
- Zuletzt bearbeitet 06.11.2025 20:05:30
A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the ar...
CVE-2022-25410
- EPSS 0.19%
- Veröffentlicht 28.02.2022 23:15:12
- Zuletzt bearbeitet 21.11.2024 06:52:08
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.
CVE-2022-25411
- EPSS 10.69%
- Veröffentlicht 28.02.2022 23:15:12
- Zuletzt bearbeitet 21.11.2024 06:52:09
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-25412
- EPSS 0.39%
- Veröffentlicht 28.02.2022 23:15:12
- Zuletzt bearbeitet 21.11.2024 06:52:09
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.
CVE-2022-25413
- EPSS 0.19%
- Veröffentlicht 28.02.2022 23:15:12
- Zuletzt bearbeitet 21.11.2024 06:52:09
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
CVE-2021-27983
- EPSS 10.61%
- Veröffentlicht 10.12.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:58:56
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.