Skip to main content
CRITICAL

CVE-2026-70553

CVSS v3

9.8

CRITICAL

EPSS Score

1.3 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/database.php, appending attacker-controlled PHP statements that are executed by the web server on every su

Technical details

Published
2026-08-04
Last Modified
2026-08-05

Frequently asked questions

What is CVE-2026-70553?

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/database.php, appending attacker-controlled PHP statements that are executed by the web server on every su

Is CVE-2026-70553 actively exploited?

Active exploitation of CVE-2026-70553 has not been confirmed. Its EPSS score was 1.3% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-70553?

CVE-2026-70553 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2026-70553 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key