CVE-2026-87928
Deferred Deferred - Pending Action

Stored XSS in MaxSite CMS via Malicious HTML Upload

Vulnerability report for CVE-2026-87928, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-18

Assigner: VulnCheck

Description

MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious scripts to the uploads/_pages/ directory, which executes in visitors' browsers when the file is accessed, enabling persistent stored cross-site scripting attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-18
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
maxsite maxsite_cms From 0.94 (inc) to 109.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in MaxSite CMS versions 0.94 through 109.6. It allows any logged-in user to upload HTML files containing malicious scripts via the admin_page upload handler. The files are stored in the uploads/_pages/ directory and execute in visitors' browsers when accessed, enabling persistent attacks.

Detection Guidance

Check for unexpected HTML files in the uploads/_pages/ directory. Use commands like 'find /path/to/maxsite/uploads/_pages/ -name "*.html" -type f' to locate suspicious files. Review recent uploads via admin logs or database entries. Monitor network traffic for unusual script executions from the uploads directory.

Impact Analysis

Attackers can steal user sessions, deface the website, or trick visitors into revealing credentials through phishing. If PHP execution is enabled in the uploads directory, remote code execution (RCE) may also be possible. Visitors accessing uploaded files risk malware infections or account compromises.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations may face fines, legal liabilities, and reputational damage due to unauthorized access or data exposure resulting from the XSS flaw.

Mitigation Strategies

Remove HTML/HTM from allowed file extensions in the upload handler. Disable direct execution of scripts in the uploads directory by configuring web server rules. Update to the latest MaxSite CMS version if available. Restrict file uploads to authenticated admin users only and validate file content using magic bytes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87928. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart