CVE-2026-3395Disclosure(max-3000 / maxsite_cms)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for max-3000 maxsite_cms systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 109.2 will fix this issue. This patch is called 08937a3c5d672a242d68f53e9fccf8a748820ef3. You should upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • maxsite_cms

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-01); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
maxsite_cms

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-01: 3Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-13: 1Active Exploitation · 2026-03-01: 1Technical Details · 2026-03-01: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-08-13: 103-0103-0503-0608-13
Signal classification2 categories
Disclosure
583.3%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-013
Active Exploitation1Disclosure2
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-08-131
Disclosure1
Full discourse6 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-3395 - high 🚨 MaxSite CMS <=109.1 - Remote Code Execution > MaxSite CMS through 109.1 allows unauthenticated remote attackers to execute arbitrar... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-3395 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces a high‑severity CVE‑2026‑3395 that enables unauthenticated remote code execution in MaxSite CMS versions ≤109.1, with a linked Nuclei template for detection.

    00052335
    1.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3395 Remote Code Injection in MaxSite CMS MarkItUp Preview AJAX Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3395

    Post summary

    A remote code injection vulnerability (CVE-2026-3395) affecting the MarkItUp Preview AJAX endpoint in MaxSite CMS has been disclosed, with no PoC, exploit, or patch information provided.

    0001093
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3395 (CVSS:6.9, HIGH) is Analyzed. A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/p..https://nvd.nist.gov/vuln/detail/CVE-2026-3395 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3395 with its CVSS rating and affected function, but offers no proof of exploit, active usage, or mitigation details.

    0000021
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3395 (CVSS:6.9, HIGH) is Analyzed. A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/p..https://nvd.nist.gov/vuln/detail/CVE-2026-3395 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A CVSS 6.9 (HIGH) vulnerability (CVE-2026-3395) has been identified in MaxSite CMS up to version 109.1, affecting the eval function in a specific admin file; no PoC, exploit, or patch details are provided.

    0000022
    173 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3395 - MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection Intel Report: https://ift.tt/z0dHkbX

    Post summary

    A new vulnerability (CVE-2026-3395) affecting MaxSite CMS's preview AJAX endpoint via eval code injection has been disclosed.

    0000052
    343 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting MaxSite CMS (CVE-2026-3395) https://vuldb.com/?ctiid.348281

    Post summary

    The post reports that CVE-2026-3395 in MaxSite CMS is being actively targeted by offensive actors, but provides no PoC, exploit code, or mitigation details.

    0000096
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmax-3000maxsite_cms---

Explore more