CVE-2026-7015: MaxSite CMS Guestbook Plugin cross site scripting
A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument ftext/fslug/flimit/femail leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 109.4 is capable of addressing this issue. The name of the patch is 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7. It is suggested to upgrade the affected component. The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via htmlspecialchars() has already been fixed in the latest patch to prevent incorrect data display."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MaxSite CMSto a version that resolves this vulnerability.Fixed in 109.4Patch 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7015?
CVE-2026-7015 is classified as a high severity vulnerability due to the potential for cross site scripting attacks.
How do I fix CVE-2026-7015?
To mitigate CVE-2026-7015, update the MaxSite CMS Guestbook Plugin to a version higher than 109.3.
Who is affected by CVE-2026-7015?
CVE-2026-7015 affects users of MaxSite CMS Guestbook Plugin versions up to and including 109.3.
What types of attacks are possible with CVE-2026-7015?
CVE-2026-7015 can lead to cross site scripting attacks that may execute malicious scripts in the context of the victim's browser.
Is CVE-2026-7015 easy to exploit?
CVE-2026-7015 is considered relatively easy to exploit, allowing attackers to manipulate input fields to inject malicious scripts.