{"id":"CVE-2021-35265","details":"A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.","modified":"2026-07-09T01:25:49.968424Z","published":"2021-08-03T12:15:07.880Z","references":[{"type":"FIX","url":"https://github.com/maxsite/cms/commit/6b0ab1de9f3d471485d1347e800a9ce43fedbf1a"},{"type":"EVIDENCE","url":"https://github.com/maxsite/cms/issues/414#issue-726249183"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/maxsite/cms","events":[{"introduced":"0"},{"fixed":"8e04d9654815e9fb966db9cf1e893bb3683d61df"},{"fixed":"6b0ab1de9f3d471485d1347e800a9ce43fedbf1a"}],"database_specific":{"cpe":"cpe:2.3:a:maxsite:maxsite_cms:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"106"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v107","v106","v104","v102","v101","v100","v99","v98","v97","v0.96","v0.95","v0.94","v0.93","v0.92","v0.91","v0.90","v0.89","v0.88","v0.87.1","v0.87"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35265.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}