maxkb records
20 published records for vendor maxkb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 65%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-918 Server-Side Request Forgery (SSRF)2
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2025-66419No exploit | MaxKB vulnerable to privilege escalation through sandbox bypassmaxkb · maxkb · CWE-362 | Critical10.0 | — | 0.3% | Dec 11, 2025 |
39Monitor | CVE-2025-53928No exploit | MaxKB has RCE in MCP callmaxkb · maxkb · CWE-94 | Critical9.8 | — | 0.4% | Jul 17, 2025 |
35Monitor | CVE-2025-64511No exploit | MaxKB has SSRF in sandboxmaxkb · maxkb · CWE-918 | High8.8 | — | 0.2% | Nov 13, 2025 |
30Monitor | CVE-2025-66446No exploit | MaxKB has a Python sandbox LD_PRELOAD bypassmaxkb · maxkb · CWE-362 | High7.5 | — | 0.3% | Dec 11, 2025 |
29Monitor | CVE-2026-39420No exploit | MaxKB: Sandbox escape via LD_PRELOAD bypassmaxkb · maxkb · CWE-78 | High7.4 | — | 0.6% | Apr 13, 2026 |
29Monitor | CVE-2026-39421No exploit | MaxKB: Sandbox escape via ctypes and unhooked SYS_pkey_mprotectmaxkb · maxkb · CWE-94 | High7.4 | — | 0.5% | Apr 13, 2026 |
29Monitor | CVE-2026-39418No exploit | MaxKB: SSRF via sandbox network hook bypassmaxkb · maxkb · CWE-918 | High7.4 | — | 0.3% | Apr 13, 2026 |
28Monitor | CVE-2024-56137No exploit | MaxKB RCE vulnerability in function librarymaxkb · maxkb · CWE-78 | High7.2 | — | 0.8% | Jan 2, 2025 |
28Monitor | CVE-2025-32383No exploit | MaxKB has a reverse shell vulnerability in function librarymaxkb · maxkb · CWE-94 | High7.2 | — | 0.3% | Apr 10, 2025 |
27Monitor | CVE-2026-39422No exploit | MaxKB has Stored XSS via ChatHeadersMiddlewaremaxkb · maxkb · CWE-79 | Medium6.9 | — | 0.3% | Apr 13, 2026 |
27Monitor | CVE-2026-39423No exploit | Stored XSS via Eval Injection in EchartsRander Componentmaxkb · maxkb · CWE-79 | Medium6.9 | — | 0.3% | Apr 13, 2026 |
26Monitor | CVE-2025-64703No exploit | MaxKB has Information Leak in sandboxmaxkb · maxkb · CWE-200 | Medium6.5 | — | 0.2% | Nov 13, 2025 |
25Monitor | CVE-2025-53927No exploit | MaxKB sandbox bypassmaxkb · maxkb · CWE-94 | Medium6.3 | — | 0.2% | Jul 17, 2025 |
23Monitor | CVE-2025-48950No exploit | MaxKB Python Sandbox Bypass in Function Librarymaxkb · maxkb · CWE-276 | Medium5.8 | — | 0.4% | Jun 3, 2025 |
22Monitor | CVE-2026-39417No exploit | MaxKB: RCE via MCP stdio command injection in workflow enginemaxkb · maxkb · CWE-20 | Medium5.5 | — | 0.4% | Apr 13, 2026 |
21Monitor | CVE-2026-39424No exploit | MaxKB has CSV Injection in its Application Chat Export Functionalitymaxkb · maxkb · CWE-1236 | Medium5.3 | — | 0.5% | Apr 13, 2026 |
20Monitor | CVE-2025-4546No exploit | 1Panel-dev MaxKB Knowledge Base Module csv injectionmaxkb · maxkb · CWE-74 | Medium5.1 | — | 0.7% | May 11, 2025 |
20Monitor | CVE-2026-39425No exploit | MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Renderingmaxkb · maxkb · CWE-80 | Medium5.1 | — | 0.3% | Apr 13, 2026 |
20Monitor | CVE-2026-39426No exploit | MaxKB: Stored XSS via Unsanitized iframe_render Parsingmaxkb · maxkb · CWE-79 | Medium5.1 | — | 0.2% | Apr 13, 2026 |
12Monitor | CVE-2026-39419No exploit | MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofingmaxkb · maxkb · CWE-74 | Low3.1 | — | 0.3% | Apr 13, 2026 |
- CVE-2025-6641940Plan
MaxKB vulnerable to privilege escalation through sandbox bypass
CriticalCVSS 10.0No exploitEPSS 0%maxkb · maxkbDec 11, 2025
- CVE-2025-5392839Monitor
MaxKB has RCE in MCP call
CriticalCVSS 9.8No exploitEPSS 0%maxkb · maxkbJul 17, 2025
- CVE-2025-6451135Monitor
MaxKB has SSRF in sandbox
HighCVSS 8.8No exploitEPSS 0%maxkb · maxkbNov 13, 2025
- CVE-2025-6644630Monitor
MaxKB has a Python sandbox LD_PRELOAD bypass
HighCVSS 7.5No exploitEPSS 0%maxkb · maxkbDec 11, 2025
- CVE-2026-3942029Monitor
MaxKB: Sandbox escape via LD_PRELOAD bypass
HighCVSS 7.4No exploitEPSS 1%maxkb · maxkbApr 13, 2026
- CVE-2026-3942129Monitor
MaxKB: Sandbox escape via ctypes and unhooked SYS_pkey_mprotect
HighCVSS 7.4No exploitEPSS 0%maxkb · maxkbApr 13, 2026
- CVE-2026-3941829Monitor
MaxKB: SSRF via sandbox network hook bypass
HighCVSS 7.4No exploitEPSS 0%maxkb · maxkbApr 13, 2026
- CVE-2024-5613728Monitor
MaxKB RCE vulnerability in function library
HighCVSS 7.2No exploitEPSS 1%maxkb · maxkbJan 2, 2025
- CVE-2025-3238328Monitor
MaxKB has a reverse shell vulnerability in function library
HighCVSS 7.2No exploitEPSS 0%maxkb · maxkbApr 10, 2025
- CVE-2026-3942227Monitor
MaxKB has Stored XSS via ChatHeadersMiddleware
MediumCVSS 6.9No exploitEPSS 0%maxkb · maxkbApr 13, 2026
- CVE-2026-3942327Monitor
Stored XSS via Eval Injection in EchartsRander Component
MediumCVSS 6.9No exploitEPSS 0%maxkb · maxkbApr 13, 2026
- CVE-2025-6470326Monitor
MaxKB has Information Leak in sandbox
MediumCVSS 6.5No exploitEPSS 0%maxkb · maxkbNov 13, 2025
- CVE-2025-5392725Monitor
MaxKB sandbox bypass
MediumCVSS 6.3No exploitEPSS 0%maxkb · maxkbJul 17, 2025
- CVE-2025-4895023Monitor
MaxKB Python Sandbox Bypass in Function Library
MediumCVSS 5.8No exploitEPSS 0%maxkb · maxkbJun 3, 2025
- CVE-2026-3941722Monitor
MaxKB: RCE via MCP stdio command injection in workflow engine
MediumCVSS 5.5No exploitEPSS 0%maxkb · maxkbApr 13, 2026
- CVE-2026-3942421Monitor
MaxKB has CSV Injection in its Application Chat Export Functionality
MediumCVSS 5.3No exploitEPSS 0%maxkb · maxkbApr 13, 2026
- CVE-2025-454620Monitor
1Panel-dev MaxKB Knowledge Base Module csv injection
MediumCVSS 5.1No exploitEPSS 1%maxkb · maxkbMay 11, 2025
- CVE-2026-3942520Monitor
MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Rendering
MediumCVSS 5.1No exploitEPSS 0%maxkb · maxkbApr 13, 2026
- CVE-2026-3942620Monitor
MaxKB: Stored XSS via Unsanitized iframe_render Parsing
MediumCVSS 5.1No exploitEPSS 0%maxkb · maxkbApr 13, 2026
- CVE-2026-3941912Monitor
MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofing
LowCVSS 3.1No exploitEPSS 0%maxkb · maxkbApr 13, 2026