CVE-2026-70553
- EPSS 0.88%
- Veröffentlicht 04.08.2026 20:16:56
- Zuletzt bearbeitet 05.08.2026 20:17:17
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is co...
CVE-2026-70552
- EPSS 0.57%
- Veröffentlicht 04.08.2026 20:16:55
- Zuletzt bearbeitet 05.08.2026 15:17:13
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path r...
CVE-2026-70554
- EPSS 0.85%
- Veröffentlicht 04.08.2026 20:11:55
- Zuletzt bearbeitet 05.08.2026 15:17:13
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or cla...
CVE-2026-7016
- EPSS 0.22%
- Veröffentlicht 26.04.2026 03:15:16
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote exploitation of the attack is po...
CVE-2026-7015
- EPSS 0.22%
- Veröffentlicht 26.04.2026 02:45:13
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be ...
CVE-2026-7014
- EPSS 0.27%
- Veröffentlicht 26.04.2026 02:30:20
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may be initiated remotely. The exp...
CVE-2026-7013
- EPSS 0.22%
- Veröffentlicht 26.04.2026 02:00:20
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. Th...
CVE-2026-7011
- EPSS 0.27%
- Veröffentlicht 26.04.2026 01:15:59
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lea...
CVE-2026-7012
- EPSS 0.29%
- Veröffentlicht 26.04.2026 01:15:16
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be launched remotely. The exploit ...
CVE-2026-3395
- EPSS 3.25%
- Veröffentlicht 01.03.2026 14:16:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code...