Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious scripts to the uploads/_pages/ directory, which executes in visitors' browsers when the file is accessed, enabling persistent stored cross-site scripting attacks. | |
| Title | MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page | |
| First Time appeared |
Max-3000
Max-3000 maxsite Cms |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:max-3000:maxsite_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Max-3000
Max-3000 maxsite Cms |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-09T16:44:59.356Z
Reserved: 2026-09-09T16:12:25.344Z
Link: CVE-2026-87928
No data.
Status : Received
Published: 2026-09-09T17:17:53.697
Modified: 2026-09-09T17:17:53.697
Link: CVE-2026-87928
No data.
OpenCVE Enrichment
Updated: 2026-09-09T18:30:13Z