Записи max-3000
8 опубликованных записей вендора max-3000.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 12,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-284 Improper Access Control2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-27983Эксплойта нет | Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.max-3000 · maxsite cms | Критическая9,8 | — | 3,5 % | 10 дек. 2021 г. |
40В плане | CVE-2022-25411Эксплойта нет | A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted Pmax-3000 · maxsite cms · CWE-434 | Критическая9,8 | — | 3,0 % | 28 февр. 2022 г. |
32Наблюдать | CVE-2022-25412Эксплойта нет | Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via themax-3000 · maxsite cms · CWE-22 | Высокая8,1 | — | 1,1 % | 28 февр. 2022 г. |
23Наблюдать | CVE-2026-3395Proof of concept | MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injectionmax-3000 · maxsite cms · CWE-74 | Средняя5,5 | — | 2,5 % | 1 мар. 2026 г. |
21Наблюдать | CVE-2022-25413Эксплойта нет | Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.max-3000 · maxsite cms · CWE-79 | Средняя5,4 | — | 0,5 % | 28 февр. 2022 г. |
21Наблюдать | CVE-2022-25410Эксплойта нет | Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/max-3000 · maxsite cms · CWE-79 | Средняя5,4 | — | 0,5 % | 28 февр. 2022 г. |
8Наблюдать | CVE-2025-12346Эксплойта нет | MaxSite CMS HTTP Header uploads-require-maxsite.php unrestricted uploadmax-3000 · maxsite cms · CWE-284 | Низкая2,1 | — | 0,4 % | 27 окт. 2025 г. |
8Наблюдать | CVE-2025-12347Эксплойта нет | MaxSite CMS save-file-ajax.php unrestricted uploadmax-3000 · maxsite cms · CWE-284 | Низкая2,1 | — | 0,4 % | 27 окт. 2025 г. |
- CVE-2021-2798340В плане
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %max-3000 · maxsite cms10 дек. 2021 г.
- CVE-2022-2541140В плане
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted P
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %max-3000 · maxsite cms28 февр. 2022 г.
- CVE-2022-2541232Наблюдать
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %max-3000 · maxsite cms28 февр. 2022 г.
- CVE-2026-339523Наблюдать
MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
СредняяCVSS 5,5Proof of conceptEPSS 2 %max-3000 · maxsite cms1 мар. 2026 г.
- CVE-2022-2541321Наблюдать
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %max-3000 · maxsite cms28 февр. 2022 г.
- CVE-2022-2541021Наблюдать
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/
СредняяCVSS 5,4Эксплойта нетEPSS 0 %max-3000 · maxsite cms28 февр. 2022 г.
- CVE-2025-123468Наблюдать
MaxSite CMS HTTP Header uploads-require-maxsite.php unrestricted upload
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %max-3000 · maxsite cms27 окт. 2025 г.
- CVE-2025-123478Наблюдать
MaxSite CMS save-file-ajax.php unrestricted upload
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %max-3000 · maxsite cms27 окт. 2025 г.