MaxSite CMS 109.6 及更早版本存在本地文件包含(LFI)漏洞,位于 和 调度器中。该漏洞允许未认证的攻击者通过提供经过 Base64 编码的路径遍历序列,执行具有特权权限的处理文件。攻击者可绕过路径校验机制,无需身份验证即可执行通常受管理员权限保护的处理操作,从而访问敏感功能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MaxSite | MaxSite CMS | 0.78 ~ 109.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87929 | 9.8 CRITICAL | MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key |
| CVE-2026-87930 | 8.1 HIGH | MaxSite CMS through 109.6 PHP Object Injection via ci_session |
| CVE-2026-87928 | 5.4 MEDIUM | MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page |
No comments yet