Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality. | |
| Title | MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher | |
| First Time appeared |
Max-3000
Max-3000 maxsite Cms |
|
| Weaknesses | CWE-98 | |
| CPEs | cpe:2.3:a:max-3000:maxsite_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Max-3000
Max-3000 maxsite Cms |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-09T18:08:20.929Z
Reserved: 2026-09-09T16:12:19.611Z
Link: CVE-2026-87927
Updated: 2026-09-09T18:08:17.533Z
Status : Received
Published: 2026-09-09T17:17:53.520
Modified: 2026-09-09T19:17:50.730
Link: CVE-2026-87927
No data.
OpenCVE Enrichment
Updated: 2026-09-09T18:30:13Z