cbcvebase.

Max-3000 Maxsite Cms vulnerabilities

8 known vulnerabilities affecting max-3000/maxsite_cms.

Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-3395P1CRITICALCVSS 9.8ExploitedPoCfixed in 109.22026-03-01
CVE-2026-3395 [CRITICAL] CWE-74 CVE-2026-3395: A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file applica A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit has been published and may be us
nvd
CVE-2025-12346P3HIGHCVSS 8.8≤ 1092025-10-28
CVE-2025-12346 [HIGH] CWE-284 CVE-2025-12346: A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of th A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the argument X-Requested-FileName/X-Requested-FileUpDir results in unrestricted upload. Remote exploitation o
nvd
CVE-2025-12347P3HIGHCVSS 8.8≤ 1092025-10-28
CVE-2025-12347 [HIGH] CWE-284 CVE-2025-12347: A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the fi A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to unrestricted upload. The attack can be executed remotely. The exploit has been published and may be used. The vend
nvd
CVE-2021-27983P3CRITICALCVSS 9.8v107.52021-12-10
CVE-2021-27983 [CRITICAL] CVE-2021-27983: Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page. Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
nvd
CVE-2022-25411P3CRITICALCVSS 9.8v1082022-02-28
CVE-2022-25411 [CRITICAL] CWE-434 CVE-2022-25411: A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers t A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
nvd
CVE-2022-25412P3HIGHCVSS 8.1v1082022-02-28
CVE-2022-25412 [HIGH] CWE-22 CVE-2022-25412: Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admi Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.
nvd
CVE-2022-25413P4MEDIUMCVSS 5.4v1082022-02-28
CVE-2022-25413 [MEDIUM] CWE-79 CVE-2022-25413: Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
nvd
CVE-2022-25410P4MEDIUMCVSS 5.4v1082022-02-28
CVE-2022-25410 [MEDIUM] CWE-79 CVE-2022-25410: Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.
nvd
Max-3000 Maxsite Cms vulnerabilities | cvebase