CVE-2026-70553 (matched: php)

  • Wednesday, 5th August, 2026
  • 16:05pm

A serious security vulnerability has been found in MaxSite CMS that could impact any site running this content management system. The flaw allows unauthenticated attackers (people who do not have any login credentials for your site) to inject malicious code into your site’s core configuration file. Attackers can send specially crafted requests to your site’s install endpoint even after you have finished setting up MaxSite, using a manipulated database prefix setting to slip the harmful code into the config. The injected code runs automatically every time a visitor loads any page on your site, with the same permissions as your web server. This gives attackers the ability to run any code they want on your server without needing to log in, which could let them take full control of your site, steal sensitive data, alter your site’s content, or use your site to harm your visitors.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-70553

« Back