pdnuclei-bot@pdnuclei_botDisclosure
The post announces a high‑severity CVE‑2026‑3395 that enables unauthenticated remote code execution in MaxSite CMS versions ≤109.1, with a linked Nuclei template for detection.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A remote code injection vulnerability (CVE-2026-3395) affecting the MarkItUp Preview AJAX endpoint in MaxSite CMS has been disclosed, with no PoC, exploit, or patch information provided.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-3395 with its CVSS rating and affected function, but offers no proof of exploit, active usage, or mitigation details.
CRAC Learning - Tech@cracbotDisclosure
A CVSS 6.9 (HIGH) vulnerability (CVE-2026-3395) has been identified in MaxSite CMS up to version 109.1, affecting the eval function in a specific admin file; no PoC, exploit, or patch details are provided.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
A new vulnerability (CVE-2026-3395) affecting MaxSite CMS's preview AJAX endpoint via eval code injection has been disclosed.
VulDB 🛡@vuldbActive Exploitation
The post reports that CVE-2026-3395 in MaxSite CMS is being actively targeted by offensive actors, but provides no PoC, exploit code, or mitigation details.