{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-87928","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-09T16:12:25.344Z","datePublished":"2026-09-09T16:44:59.356Z","dateUpdated":"2026-09-09T16:44:59.356Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-09T16:44:59.356Z"},"datePublic":"2026-09-09T00:00:00.000Z","title":"MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page","descriptions":[{"lang":"en","value":"MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious scripts to the uploads/_pages/ directory, which executes in visitors' browsers when the file is accessed, enabling persistent stored cross-site scripting attacks."}],"tags":["x_open-source","unsupported-when-assigned"],"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-434","description":"Unrestricted Upload of File with Dangerous Type","type":"CWE"}]}],"affected":[{"defaultStatus":"unaffected","vendor":"MaxSite","product":"MaxSite CMS","packageURL":"pkg:github/maxsite/cms","repo":"https://github.com/maxsite/cms","versions":[{"version":"0.94","lessThanOrEqual":"109.6","status":"affected","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:max-3000:maxsite_cms:*:*:*:*:*:*:*:*","versionStartIncluding":"0.94","versionEndIncluding":"109.6"}]}]}],"metrics":[{"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","subIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","version":"4.0","baseSeverity":"MEDIUM","baseScore":5.1,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}},{"cvssV3_1":{"attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","version":"3.1","baseSeverity":"MEDIUM","baseScore":5.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}}],"references":[{"url":"https://github.com/maxsite/cms","tags":["product"]},{"url":"https://github.com/EviL0rd/maxsite-cve2/blob/main/2026.09.08-maxsite-cms-arbitrary-file-write-stored-xss.md","tags":["exploit","technical-description"]},{"url":"https://github.com/maxsite/cms/blob/2ca0a0c7d1d71106a25dbb0f2aedaaefbf12802c/application/maxsite/admin/plugins/admin_page/uploads-require-maxsite.php#L1-L64","tags":["technical-description"]},{"name":"VulnCheck Advisory: MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/maxsite-cms-0.94-through-109.6-html-upload-xss-via-admin-page"}],"credits":[{"lang":"en","value":"EVIL0RD","type":"reporter"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"vulncheck-endgame"}}}}