PT-2026-35196 · Unknown+1 · Maxsite Cms+1

Konchan

·

Published

2026-04-26

·

Updated

2026-04-26

·

CVE-2026-7015

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MaxSite CMS versions prior to 109.4
Description A cross-site scripting issue exists in the Guestbook Plugin component due to improper processing of the f text, f slug, f limit, and f email arguments. This occurs because of a lack of filtering via the htmlspecialchars() function, which is used to convert special characters to HTML entities to prevent the browser from interpreting them as code. This flaw allows a remote attacker to execute malicious scripts.
Recommendations Update to version 109.4.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7015

Affected Products

Guestbook Plugin
Maxsite Cms