CVE-2026-87928 PUBLISHED

MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page

Assigner: VulnCheck
Reserved: 09.09.2026 Published: 09.09.2026 Updated: 09.09.2026

MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious scripts to the uploads/_pages/ directory, which executes in visitors' browsers when the file is accessed, enabling persistent stored cross-site scripting attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor MaxSite
Product MaxSite CMS
Versions Default: unaffected
  • affected from 0.94 to 109.6 (incl.)

Credits

  • EVIL0RD reporter

References

Problem Types

  • Unrestricted Upload of File with Dangerous Type CWE