A security vulnerability has been found in MaxSite CMS, a content management system some website owners use to build and manage their sites. This flaw allows anyone without login access to your site to run harmful, unauthorized code on your web server by sending a single specially crafted request that includes a malicious value in the maxsite_comuser cookie stored by the CMS.
The CMS processes this cookie data without proper validation or security checks, letting attackers exploit hidden system functionality to take control of your site. If successfully exploited, this could let attackers steal your site’s data, change your site’s content, or use your server for other malicious activities.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-70554