CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-70553 — MaxSite CMS contains a remote code execution vulnerability that allows unauthent...

·Source: NIST NVD

Updated:

Executive Summary

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/databa

Analysis

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/database.php, appending attacker-controlled PHP statements that are executed by the web server on every subsequent request, resulting in persistent unauthenticated remote code execution as the web-server process user. CVSS Score: 9.8. Published: 2026-08-04T20:16:56.023.

Indicators of Compromise (1)

CVE (1)
CVE-2026-70553
Source Attribution

Originally published by NIST NVD on Aug 4, 2026. Verified by: NIST.

Related Threats

MEDIUMVulnerabilityNEW

Senate Committee Advances Health Data Privacy Bill

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/senate-committee-advances-health-data-privacy-bill-image_small-10-a-32415.jpg" align=right hspace=4><b>Move Comes as Regulators Plan to Finalize Modifications to HIPAA Privacy Rule</b><br>Federal regulators are slated this month to issue a final rule modifying the HIPAA Privacy Rule. Meanwhile, an influential Senate committee late

Bank Info Security
CRITICALVulnerability

NVD CRITICAL: CVE-2026-70554 — MaxSite CMS contains a PHP object injection vulnerability that allows unauthenti...

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during obje

CVE-2026-70554
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-18813 — A vulnerability has been found in H3C NX15 V100R017. This affects the function d...

A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.

CVE-2026-18813
NIST NVD