Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-87927

Опубликовано: 09 сент. 2026
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.

EPSS

Процентиль: 27%
0.00337
Низкий

8.2 High

CVSS3

Дефекты

CWE-98

Связанные уязвимости

CVSS3: 8.2
github
14 дней назад

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.

EPSS

Процентиль: 27%
0.00337
Низкий

8.2 High

CVSS3

Дефекты

CWE-98