A security flaw has been discovered in MaxSite CMS, a platform some website owners use to manage their sites. This vulnerability lets attackers who do not have login credentials for your site run harmful, unauthorized code on sites running affected versions of the platform.
To exploit this flaw, an attacker only needs to send one specially crafted request to a vulnerable site, with a malicious value included in the maxsite_comuser cookie. No valid login or special access is required to carry out the attack.
If the attack is successful, the attacker could gain full control of the affected site. This could allow them to steal visitor data, alter or deface the site’s public content, or use the compromised site to target people who visit it.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-70554