PatchSiren

MaxSite CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL MaxSite CVE published 2026-09-09

CVE-2026-87929

CVE-2026-87929 is a critical vulnerability in MaxSite CMS versions through 109.6. The vulnerability stems from a hardcoded session encryption key in the application/config/config.php file, which is never changed during installation. This allows unauthenticated attackers to forge administrator session cookies by computing an HMAC-SHA1 using the publicly known encryption key, effectively bypassing authentic [truncated]

MEDIUM MaxSite CVE published 2026-09-09

CVE-2026-87928

CVE-2026-87928 is a cross-site scripting vulnerability in MaxSite CMS versions 0.94 through 109.6. The vulnerability allows any logged-in user to upload HTML files containing malicious scripts to the uploads/_pages/ directory, which executes in visitors' browsers when accessed, enabling persistent stored cross-site scripting attacks. This vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. Def [truncated]

CRITICAL MaxSite CVE published 2026-08-04

CVE-2026-70554

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. The vulnerability can be exploited by crafting a malicious serialized PHP object payload delivered in a single HTTP request, triggering magic [truncated]

CRITICAL MaxSite CVE published 2026-08-04

CVE-2026-70553

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:56.023Z and has not been modified since then. CVE-2026-70553 is a critical vulnerability in MaxSite CMS with a CVSS score of 9.3, allowing unauthenticated remote code execution. The vulnerability is caused by improper handling of user input in the install endpoint, which can be exploited by [truncated]

CRITICAL MaxSite CVE published 2026-08-04

CVE-2026-70552

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.883Z and has not been modified since then. The NVD entry is currently Received. CVE-2026-70552 is a critical vulnerability in MaxSite CMS 109.5 and earlier, allowing unauthenticated attackers to bypass authentication and access admin-gated endpoints. This vulnerability exists in the AJAX [truncated]