All 7 CVE vulnerabilities found in MaxSite CMS, with AI-generated Chinese analysis, references, and POCs.
Vendor: MaxSite
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-87930 | MaxSite CMS through 109.6 PHP Object Injection via ci_session CWE-502 | 8.1 | High | 2026-09-09 |
| CVE-2026-87929 | MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key CWE-321 | 9.8 | Critical | 2026-09-09 |
| CVE-2026-87928 | MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page CWE-434 | 5.4 | Medium | 2026-09-09 |
| CVE-2026-87927 | MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher CWE-98 | 8.2 | High | 2026-09-09 |
| CVE-2026-70554 | MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie CWE-502 | 9.8 | Critical | 2026-08-04 |
| CVE-2026-70553 | MaxSite CMS Unauthenticated RCE via Install Endpoint CWE-94 | 9.8 | Critical | 2026-08-04 |
| CVE-2026-70552 | MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php CWE-306 | 9.8 | Critical | 2026-08-04 |
All 7 known CVE vulnerabilities affecting MaxSite CMS with full Chinese analysis, references, and POCs where available.