CVE-2026-87929
- EPSS 0.29%
- Veröffentlicht 09.09.2026 16:45:00
- Zuletzt bearbeitet 14.09.2026 14:17:18
MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malici...
CVE-2026-87930
- EPSS 0.34%
- Veröffentlicht 09.09.2026 16:45:00
- Zuletzt bearbeitet 09.09.2026 20:14:00
MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magi...
CVE-2026-87928
- EPSS 0.17%
- Veröffentlicht 09.09.2026 16:44:59
- Zuletzt bearbeitet 18.09.2026 18:17:35
MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious scripts to the uploads/_pages/ d...
CVE-2026-87927
- EPSS 0.34%
- Veröffentlicht 09.09.2026 16:44:58
- Zuletzt bearbeitet 09.09.2026 20:14:00
MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attack...
CVE-2026-70553
- EPSS 0.88%
- Veröffentlicht 04.08.2026 20:16:56
- Zuletzt bearbeitet 31.08.2026 20:19:42
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is co...
CVE-2026-70552
- EPSS 0.57%
- Veröffentlicht 04.08.2026 20:16:55
- Zuletzt bearbeitet 31.08.2026 20:19:42
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path r...
CVE-2026-70554
- EPSS 0.85%
- Veröffentlicht 04.08.2026 20:11:55
- Zuletzt bearbeitet 31.08.2026 20:19:42
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or cla...
CVE-2026-37700
- EPSS 0.19%
- Veröffentlicht 03.06.2026 00:00:00
- Zuletzt bearbeitet 22.07.2026 20:10:00
Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page
CVE-2023-36291
- EPSS 0.49%
- Veröffentlicht 03.07.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:30
Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.
CVE-2021-35265
- EPSS 3.44%
- Veröffentlicht 03.08.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:10
A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.