---
id: CVE-2025-12346
title: A vulnerability was detected in MaxSite CMS up to 109
summary: >-
  A vulnerability was detected in MaxSite CMS up to 109. This vulnerability
  affects unknown code of the file
  application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the
  component HTTP Header Handler. Performing manipulat…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-284
  - CWE-434
  - CWE-434
vendor: max-3000
product: maxsite_cms
affected:
  - maxsite_cms <= 109
published: '2025-10-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12346'
references:
  - url: 'https://note-hxlab.wetolink.com/share/8QmDZCddHvyR'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.330136'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.330136'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.674551'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00396
epssPercentile: 0.31706
ingestedAt: '2026-10-08T11:31:27.659Z'
---

## Overview

A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulation of the argument X-Requested-FileName/X-Requested-FileUpDir results in unrestricted upload. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `maxsite_cms <= 109`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
