MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. The vulnerability can be exploited by crafting a malicious serialized PHP object payload delivered in a single HTTP request, triggering magic [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:56.023Z and has not been modified since then. CVE-2026-70553 is a critical vulnerability in MaxSite CMS with a CVSS score of 9.3, allowing unauthenticated remote code execution. The vulnerability is caused by improper handling of user input in the install endpoint, which can be exploited by [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.883Z and has not been modified since then. The NVD entry is currently Received. CVE-2026-70552 is a critical vulnerability in MaxSite CMS 109.5 and earlier, allowing unauthenticated attackers to bypass authentication and access admin-gated endpoints. This vulnerability exists in the AJAX [truncated]