Max-3000
4 CVEs tracked since 2022. Since Feb 2022, none of them reached CISA KEV.
Max-3000 CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-02 | 4 | 0 |
Products
The products that kept showing up in Max-3000's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 8 most recently published vulnerabilities affecting Max-3000.
- CVE-2026-3395MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection7.3
- CVE-2025-12347MaxSite CMS save-file-ajax.php unrestricted upload6.3
- CVE-2025-12346MaxSite CMS HTTP Header uploads-require-maxsite.php unrestricted upload6.3
- CVE-2022-25413Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.5.4
- CVE-2022-25412Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.8.1
- CVE-2022-25411A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.9.8
- CVE-2022-25410Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.5.4
- CVE-2021-27983Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.9.8
The record
- Peak rank
- #132 in Feb 2022
- Busiest month shown
- Feb 2022, 4 CVEs
- Months with a KEV entry
- 0 since Feb 2022
- Monthly snapshots
- 1 since 2022