CVE-2026-7014: MaxSite CMS down_count Plugin cross site scripting
A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component downcount Plugin. This manipulation of the argument ffile/fprefix causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 109.4 is able to resolve this issue. Patch name: 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7. The affected component should be upgraded. The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via htmlspecialchars() has already been fixed in the latest patch to prevent incorrect data display."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MaxSite CMS down_count Pluginto a version that resolves this vulnerability.Fixed in 109.4Patch 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7014?
CVE-2026-7014 is considered a medium severity vulnerability due to its potential for remote cross-site scripting attacks.
How do I fix CVE-2026-7014?
To fix CVE-2026-7014, update the MaxSite CMS down_count Plugin to a version later than 109.3.
What types of attacks can be executed using CVE-2026-7014?
CVE-2026-7014 allows attackers to execute cross-site scripting (XSS) attacks, potentially compromising user data.
Who is affected by CVE-2026-7014?
Users of MaxSite CMS versions up to and including 109.3 with the down_count Plugin installed are affected by CVE-2026-7014.
Can CVE-2026-7014 be exploited remotely?
Yes, CVE-2026-7014 can be exploited remotely, making it crucial for users to address this vulnerability promptly.