Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Maxkb

First CVE: Jan 2, 2025Active for: 2 yearsTotal CVEs: 21
34.5
VTI Score
Medium

Maxkb is a modestly represented vendor focused on a single knowledge-base and document-management product that has drawn a meaningful share of critical-severity disclosures. The vulnerability pattern recurs across input-handling and code-execution boundaries: code injection, cross-site scripting, OS command injection, and race conditions reflect the architectural risk of a web-facing application that processes and executes user-supplied or templated content. Defenders deploying this product should prioritize input validation, output encoding, and access control hardening; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
10.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Maxkb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 2, 2025
18 months ago
Most Recent CVE
Jun 25, 2026
29 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-66419CRITICAL
MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under
Dec 11, 202510.030NONO
CVE-2026-56779MEDIUM
MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by
Jun 25, 20266.429NONO
CVE-2026-39418HIGH
MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypassed by using socket.sendto() with the MSG_FASTOPEN flag. Th
Apr 14, 20267.429NONO
CVE-2025-64511HIGH
MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool modul
Nov 13, 20258.828NONO
CVE-2025-53928CRITICAL
MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts an
Jul 17, 20259.828NONO
CVE-2026-39421HIGH
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in the ToolExecutor component. By leveraging Python's ctypes li
Apr 14, 20267.425NONO
CVE-2026-39420HIGH
MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mechanism allows an authenticated user with tool execution privil
Apr 14, 20267.425NONO
CVE-2025-66446HIGH
MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and othe
Dec 11, 20257.525NONO
CVE-2025-48950HIGH
MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as `/
Jun 3, 20258.824NONO
CVE-2025-4546HIGH
A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Knowledge
May 11, 20258.824NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
43%
43%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (9.5%)
Network19 (90.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (90.5%)
High2 (9.5%)
Unknown0 (0.0%)
User Interaction
None16 (76.2%)
Unknown0 (0.0%)
Required5 (23.8%)
Privileges Required
Low16 (76.2%)
High3 (14.3%)
None2 (9.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Maxkb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Maxkb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Maxkb's Products

View all 3 CNAs →

Top CWEs