Remote Code Execution Vulnerability in MaxSite CMS by MaxSite
CVE-2026-70553

9.3CRITICAL

Key Information:

Vendor

Maxsite

Vendor
CVE Published:
4 August 2026

What is CVE-2026-70553?

MaxSite CMS contains a vulnerability that enables unauthenticated attackers to execute arbitrary PHP code on the server. By submitting specially crafted POST requests to the install endpoint, attackers can manipulate the application configuration file, particularly the database connection settings. This occurs through the injection of a malicious db_dbprefix value, which allows for the execution of custom PHP statements by breaking out of a standard string literal. As a result, the attacker can maintain persistent control over the affected system, as these malicious commands are executed by the server on each subsequent request.

Affected Version(s)

MaxSite CMS 105.2 <= 109.5

MaxSite CMS 105.2 <= 109.5

MaxSite CMS 109.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amir Aliu & Enrik Mustafa
.