CVE-2026-37700: XSS
Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by adminpage
Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by adminpage
The severity of CVE-2026-37700 is classified as medium with a CVSS score of 4.1.
CVE-2026-37700 is a Cross Site Scripting vulnerability in MaxSite CMS v.109.2 that allows a remote attacker to obtain sensitive information.
To mitigate CVE-2026-37700, ensure that your MaxSite CMS is updated to a version that addresses this vulnerability and apply any relevant security patches.
Users of MaxSite CMS version 109.2 are affected by CVE-2026-37700 due to its vulnerability in the Backend page file upload endpoint.
CVE-2026-37700 is classified as an XSS (Cross Site Scripting) vulnerability.