CVE-2026-70554
MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.
| CWE | CWE-502 |
| Vendor | maxsite |
| Product | maxsite cms |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for maxsite maxsite cms
Be the first to know when new critical vulnerabilities affecting maxsite maxsite cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
MaxSite / MaxSite CMS
0.78 โค 109.5
References
Credits
๐ Amir Aliu & Enrik Mustafa