CVE-2026-87930
MaxSite CMS versions up to 109.6 can unserialize a crafted session cookie without class restrictions. This allows attackers to inject PHP objects, potentially corrupting the application or executing code.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Website owners and administrators running MaxSite CMS version 109.6 or earlier.
Real-world impact
An attacker can forge a session cookie that, when accepted by the site, triggers PHP magic methods to alter data or run arbitrary code, effectively taking control of the website.
Why this severity
The CVSS score of 9.2 indicates the flaw is network‑exploitable, requires no user interaction, and can lead to full compromise of the application’s state and code execution.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources