Remote Code Execution Vulnerability in MaxSite CMS by MaxSite
CVE-2026-70553
9.3CRITICAL
What is CVE-2026-70553?
MaxSite CMS contains a vulnerability that enables unauthenticated attackers to execute arbitrary PHP code on the server. By submitting specially crafted POST requests to the install endpoint, attackers can manipulate the application configuration file, particularly the database connection settings. This occurs through the injection of a malicious db_dbprefix value, which allows for the execution of custom PHP statements by breaking out of a standard string literal. As a result, the attacker can maintain persistent control over the affected system, as these malicious commands are executed by the server on each subsequent request.
Affected Version(s)
MaxSite CMS 105.2 <= 109.5
MaxSite CMS 105.2 <= 109.5
MaxSite CMS 109.6
