MaxSite CMS

4 known vulnerabilities in MaxSite CMS, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-87930 CVSS 9.2 critical MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to…
  • CVE-2026-87929 CVSS 9.3 critical MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during…
  • CVE-2026-87928 CVSS 5.1 medium MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any…
  • CVE-2026-87927 CVSS 8.8 high MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows…