Cross-Site Scripting Vulnerability in MaxSite CMS by MaxSite
CVE-2026-87928
Key Information:
- Vendor
Maxsite
- Status
- Vendor
- CVE Published:
- 9 September 2026
Badges
What is CVE-2026-87928?
MaxSite CMS versions 0.94 through 109.6 are plagued by a cross-site scripting vulnerability located within the admin_page upload handler. This flaw permits any authenticated user to upload HTML files, which may contain malicious scripts. Once these files are placed in the uploads/_pages/ directory, they execute in the browsers of visitors accessing the site, leading to persistent stored cross-site scripting attacks that can compromise user data.
Affected Version(s)
MaxSite CMS 0.94 <= 109.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
