MaxSite CMS Redirect Plugin Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in MaxSite CMS versions prior to 109.3, specifically within the Redirect Plugin. The issue arises from the improper sanitization of user input in the 'f_all' and 'f_all404' arguments, allowing attackers to inject malicious scripts. This vulnerability can be exploited remotely and is now public knowledge.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Reproduction

To reproduce this vulnerability, upload a script to a server running MaxSite CMS version 109.3 or earlier. Then, use the Redirect Plugin to create a redirect that includes the 'f_all' or 'f_all404' arguments. The injected script will be executed when the redirect is accessed.

Remediation

Users are advised to upgrade to MaxSite CMS version 109.4 or later, where this vulnerability has been addressed.

Added: Apr 26, 2026, 2:18 AM
Updated: Apr 26, 2026, 2:18 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
6.5
remediation
7.7
relevance
6.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.