Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MaxSite — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting MaxSite. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MaxSite is a content management system designed for creating and managing websites with a focus on simplicity and extensibility. Historically, it has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The platform's modular architecture has contributed to consistent security challenges, with nine CVEs documented to date. While no major public security incidents have been widely reported, the pattern of vulnerabilities suggests potential risks for unpatched installations, particularly in environments where default configurations or outdated versions remain in use.

Top products by MaxSite: CMS MaxSite CMS
CVE ID Title CVSS Severity Published
CVE-2026-87930 MaxSite CMS through 109.6 PHP Object Injection via ci_session — MaxSite CMS CWE-502 8.1 High 2026-09-09
CVE-2026-87929 MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key — MaxSite CMS CWE-321 9.8 Critical 2026-09-09
CVE-2026-87928 MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page — MaxSite CMS CWE-434 5.4 Medium 2026-09-09
CVE-2026-87927 MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher — MaxSite CMS CWE-98 8.2 High 2026-09-09
CVE-2026-70554 MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie — MaxSite CMS CWE-502 9.8 Critical 2026-08-04
CVE-2026-70553 MaxSite CMS Unauthenticated RCE via Install Endpoint — MaxSite CMS CWE-94 9.8 Critical 2026-08-04
CVE-2026-70552 MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php — MaxSite CMS CWE-306 9.8 Critical 2026-08-04
CVE-2026-7016 MaxSite CMS ushki Plugin cross site scripting — CMS CWE-79 2.4 Low 2026-04-26
CVE-2026-7015 MaxSite CMS Guestbook Plugin cross site scripting — CMS CWE-79 2.4 Low 2026-04-26
CVE-2026-7014 MaxSite CMS down_count Plugin cross site scripting — CMS CWE-79 2.4 Low 2026-04-26
CVE-2026-7013 MaxSite CMS mail_send Plugin cross site scripting — CMS CWE-79 2.4 Low 2026-04-26
CVE-2026-7012 MaxSite CMS Redirect Plugin cross site scripting — CMS CWE-79 2.4 Low 2026-04-26
CVE-2026-7011 MaxSite CMS Antispam Plugin plugin_antispam cross site scripting — CMS CWE-79 2.4 Low 2026-04-26
CVE-2026-3395 MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection — CMS CWE-94 7.3 High 2026-03-01
CVE-2025-12347 MaxSite CMS save-file-ajax.php unrestricted upload — CMS CWE-434 6.3 Medium 2025-10-28
CVE-2025-12346 MaxSite CMS HTTP Header uploads-require-maxsite.php unrestricted upload — CMS CWE-434 6.3 Medium 2025-10-28

This page lists every published CVE security advisory associated with MaxSite. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.