CVE-2026-3395
published 2026-03-01CVE-2026-3395: A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php…
PriorityP183critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
3.88%
89.5th percentile
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 109.2 will fix this issue. This patch is called 08937a3c5d672a242d68f53e9fccf8a748820ef3. You should upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| max-3000 | maxsite_cms | < 109.2 | 109.2 |
| maxsite | cms | — | — |
| maxsite | cms | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g6fv-7p3q-j4fc: A flaw has been found in MaxSite CMS up to 109
ghsa_unreviewed·2026-03-01
CVE-2026-3395 [MEDIUM] CWE-74 GHSA-g6fv-7p3q-j4fc: A flaw has been found in MaxSite CMS up to 109
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 109.2 will fix this issue. This patch is called 08937a3c5d672a242d68f53e9fccf8a748820ef3. You should upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.
VulnCheck
max-3000 maxsite_cms Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
vulncheck·2026·CVSS 9.8
CVE-2026-3395 [CRITICAL] max-3000 maxsite_cms Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
max-3000 maxsite_cms Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 109.2 will fix this issue. This patch is called 08937a3c5d672a242d68f53e9fccf8a748820ef3. You should upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.
Affected: max-3000 maxsite_cms
Required Action: Apply remed
No detection rules found.
Nuclei
MaxSite CMS <=109.1 - Remote Code Execution
nuclei·CVSS 9.8
CVE-2026-3395 [CRITICAL] MaxSite CMS <=109.1 - Remote Code Execution
MaxSite CMS <=109.1 - Remote Code Execution
MaxSite CMS through 109.1 allows unauthenticated remote attackers to execute arbitrary code via the MarkItUp editor preview AJAX endpoint, preview-ajax.php. The endpoint insufficiently authenticates the request, failing to ensure the user is logged in, and processes the attacker's input via unsafe usage of PHP eval() on user-supplied [php]...[/php] shortcodes. By providing a POST request to the vulnerable /ajax/ endpoint with crafted input, attackers may achieve remote code execution. The issue is addressed in version 109.2 by implementing proper authentication controls.
Template:
id: CVE-2026-3395
info:
name: MaxSite CMS <=109.1 - Remote Code Execution
author: ritikchaddha
severity: high
description: |
MaxSite CMS through 109.1 allows unauth
Hackernews
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
blogs_hackernews·2026-07-13·CVSS 9.8
CVE-2026-48939 [CRITICAL] iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of zero-day exploitation in the wild.
The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below -
CVE-2026-48939 - A vulnerability in the iCagenda extension for Joomla that allows the upload of arbitrary files via the file attachment feature, leading to PHP code upload and execution.
CVE-2026-56291 -
Bugzilla
CVE-2026-31531 kernel: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()
bugzilla·2026-04-23
CVE-2026-31531 [MEDIUM] CVE-2026-31531 kernel: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()
CVE-2026-31531 kernel: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()
In the Linux kernel, the following vulnerability has been resolved:
ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()
When querying a nexthop object via RTM_GETNEXTHOP, the kernel currently
allocates a fixed-size skb using NLMSG_GOODSIZE. While sufficient for
single nexthops and small Equal-Cost Multi-Path groups, this fixed
allocation fails for large nexthop groups like 512 nexthops.
This results in the following warning splat:
WARNING: net/ipv4/nexthop.c:3395 at rtm_get_nexthop+0x176/0x1c0, CPU#20: rep/4608
[...]
RIP: 0010:rtm_get_nexthop (net/ipv4/nexthop.c:3395)
[...]
Call Trace:
rtnetlink_rcv_msg (net/core/rtnetlink.c:6989)
netlink_rcv_skb (net/netlink/af_netlink.c:2550)
netlink_unicas
2026-03-01
Published
Exploited in the wild