A critical security vulnerability has been identified in MaxSite CMS that allows unapproved, unlogged-in users to run harmful code on websites using this platform. The flaw exploits the CMS's installation setup page, which remains accessible even after you finish building your site. Attackers can send specially crafted requests to this page, manipulating the database prefix field to insert malicious code into your site's core configuration file. This malicious code runs automatically every time a visitor loads any page on your site, operating with the same permissions as your web server. This gives attackers persistent, undetected control over your site's functionality, with no need for valid login credentials.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-70553