PHP Object Injection Vulnerability in MaxSite CMS by MaxSite
CVE-2026-70554

9.3CRITICAL

Key Information:

Vendor

Maxsite

Vendor
CVE Published:
4 August 2026

What is CVE-2026-70554?

MaxSite CMS has a PHP object injection vulnerability that poses a significant risk to users. Unauthenticated attackers can exploit this flaw by injecting crafted serialized data into the 'maxsite_comuser' cookie, which is then passed to the unserialize() function without proper validation or class allowlisting. This oversight allows attackers to invoke magic methods during the deserialization process, facilitating property-oriented programming attacks or enabling remote code execution through various gadget chains, particularly those associated with the SoapClient or Imagick extensions. It is crucial for organizations using MaxSite CMS to apply the necessary patches and mitigate potential threats.

Affected Version(s)

MaxSite CMS 0.78 <= 109.5

MaxSite CMS 0.78 <= 109.5

MaxSite CMS 109.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amir Aliu & Enrik Mustafa
.