CVE-2026-7016
- EPSS 0.22%
- Veröffentlicht 26.04.2026 03:15:16
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote exploitation of the attack is po...
CVE-2026-7015
- EPSS 0.22%
- Veröffentlicht 26.04.2026 02:45:13
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be ...
CVE-2026-7014
- EPSS 0.27%
- Veröffentlicht 26.04.2026 02:30:20
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may be initiated remotely. The exp...
CVE-2026-7013
- EPSS 0.22%
- Veröffentlicht 26.04.2026 02:00:20
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. Th...
CVE-2026-7011
- EPSS 0.27%
- Veröffentlicht 26.04.2026 01:15:59
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lea...
CVE-2026-7012
- EPSS 0.29%
- Veröffentlicht 26.04.2026 01:15:16
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be launched remotely. The exploit ...
CVE-2026-3395
- EPSS 0.49%
- Veröffentlicht 01.03.2026 14:16:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code...
CVE-2025-12347
- EPSS 0.36%
- Veröffentlicht 28.10.2025 02:02:13
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricte...
CVE-2025-12346
- EPSS 0.36%
- Veröffentlicht 28.10.2025 02:02:09
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the ar...