A security flaw has been discovered in MaxSite CMS, a tool used to build and manage websites. This vulnerability allows attackers who do not have your site's login credentials to run harmful, unauthorized code on your site.
To exploit the flaw, attackers send specially crafted requests to the CMS's installation endpoint, even after your site has already been fully set up and configured. They can manipulate a specific input field to inject malicious code directly into your site's core configuration file.
This injected code runs automatically every time a visitor loads your site, with the same permissions as your web server. It gives attackers persistent, unauthenticated control over your site, allowing them to steal data, deface your content, or use your site to harm your visitors, all without ever needing access to your account.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-70553