PHP · AUGUST 2026 · CONFIRMED

MaxSite CMS Remote Code Execution Vulnerability (CVE-2026-70553)

CVE-2026-70553Severity: CRITICAL

MaxSite CMS has a confirmed remote code execution vulnerability (CVE-2026-70553) that allows unauthenticated attackers to execute arbitrary PHP code on affected installations.

What happened

MaxSite CMS versions prior to the patched release contain a critical vulnerability that permits unauthenticated remote code execution. Attackers can exploit this by submitting a specially crafted db_dbprefix value during installation, which injects malicious PHP code into the application/config/database.php file. This code is then executed by the web server on every subsequent request, granting the attacker persistent access as the web server process user.

To assess your exposure, check if you are running an affected version of MaxSite CMS. The specific vulnerable versions are not detailed in the provided sources, so consulting the primary CVE sources is recommended. If you are using MaxSite CMS, it is critical to upgrade to a patched version as soon as it is available. Additionally, review the application/config/database.php file for any unauthorized changes to detect potential exploitation.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If maxsite cms is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats