Junglewise Threat Intelligence

CVE-2026-37700: MaxSite CMS XSS in backend page file upload endpoint

CVE-2026-37700 · Severity: info · CVSS 5.4 · Published 2026-06-03

Executive brief

MaxSite CMS, a content management system, contains a security flaw in its file upload system. A user with limited access can upload malicious files that, when viewed by an administrator, allow the attacker to steal sensitive session information or perform actions on the administrator's behalf. This could lead to a full takeover of the website's management backend.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in MaxSite CMS v.109.2 due to an access control flaw in the backend file upload endpoint used by 'admin_page'. Specifically, the 'uploads-require-maxsite.php' component fails to properly validate permissions, allowing low-privileged backend users to upload HTML files. When a higher-privileged user (such as an administrator) interacts with these uploaded files, the malicious script executes within their session context. This can be used to exfiltrate session cookies or other sensitive backend data. The vulnerability stems from insufficient permission checks in the 'admin_page' plugin routing compared to other administrative functions.

Affected products

  • MaxSite CMS MaxSite CMS 109.2

Timeline

  • 2026-06-03: disclosed: CVE published to NVD dataset

References