CVE-2026-7011Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 109.4 addresses this issue. This patch is called 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7. Upgrading the affected component is advised. The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via `htmlspecialchars()` has already been fixed in the latest patch to prevent incorrect data display."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked at 5 mentions on most recent observed day (2026-05-23)
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
01345Mentions · 2026-04-26: 2Mentions · 2026-04-27: 1Mentions · 2026-05-23: 5Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 1Technical Details · 2026-05-23: 504-2604-2705-23
Signal classification2 categories
Disclosure
787.5%
General
112.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-262
Disclosure1General1
2026-04-271
Disclosure1
2026-05-235
Disclosure5
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    MaxSite CMS Antispam Plugin XSS: Remote Attackers Bypass Output Encoding (CVE-2026-7011) MaxSite CMS, a no-code CMS platform popular in Eastern European small business and hosting provider ecosystems, disclosed a critical XSS vulnerability in its Antispam plugin on April…

    Post summary

    MaxSite CMS announced a critical XSS flaw (CVE‑2026‑7011) in its Antispam plugin, noting that remote attackers can bypass output encoding. No PoC, exploit, or patch details are provided in the excerpt.

    1000049
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    26, 2026. — MaxSite CMS Antispam Plugin XSS: Remote Attackers Bypass Output Encoding in /admin/pluginantispam (CVE-2026-7011). MaxSite CMS, a no-code CMS platform popular in Eastern European small business and hosting provider ecosystems, disclosed a critical XSS…

    Post summary

    The text announces the disclosure of CVE-2026-7011, a critical XSS flaw in MaxSite CMS's Antispam Plugin, but provides no PoC, exploit code, active exploitation evidence, or patch details.

    1000054
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-7011 · 109.3 → 109.4 MaxSite CMS Antispam Plugin XSS: Remote Attackers Bypass Output Encoding (CVE-2026-7011)

    Post summary

    The message announces the CVE-2026-7011, noting it is an XSS flaw in the MaxSite CMS Antispam Plugin that allows remote attackers to bypass output encoding.

    1000049
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    MaxSite CMS Antispam Plugin XSS: Remote Attackers Bypass Output Encoding (CVE-2026-7011) MaxSite CMS, a no-code CMS platform popular in Eastern European small business and hosting provider ecosystems, disclosed a critical XSS vulnerability in its Antispam plugin on April…

    Post summary

    The post announces a newly disclosed XSS flaw (CVE-2026-7011) in MaxSite CMS Antispam plugin, detailing the nature of the bypass but not providing PoC, exploit, or patch information.

    1000045
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources BitNinja Security: Critical CVE-2026-7011 Vulnerability in MaxSite CMS OffSeq Threat Radar: CVE-2026-7011 Cross Site Scripting in MaxSite CMS MaxSite CMS Antispam Plugin XSS: Remote Attackers Bypass Output Encoding (CVE-2026-7011)

    Post summary

    The text announces the Cross‑Site Scripting vulnerability CVE‑2026‑7011 in MaxSite CMS’s Antispam Plugin, but offers no PoC, exploit, or patch details.

    1000045
    227 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7011 A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the componen… https://www.cve.org/CVERecord?id=CVE-2026-7011

    Post summary

    The text announces CVE-2026-7011 as a weakness in MaxSite CMS up to version 109.3, providing a brief component path but no evidence of exploitation, patching, or false positive.

    00010128
    57.3K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7011 📊 Severity: 2.4 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7011 #CVE-2026-7011 #CVE #Low #CyberSecurity #InfoSec https://t.co/klBHwLb3Bl

    Post summary

    The post merely announces a low‑severity CVE-2026‑7011 with a reference to NVD, providing no technical details, exploit evidence, or mitigation information.

    0000036
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7011 Cross Site Scripting in MaxSite CMS Antispam Plugin Up to 109.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7011 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new Cross‑Site Scripting vulnerability (CVE‑2026‑7011) affecting MaxSite CMS Antispam Plugin up to version 109.3 has been announced via a vulnerability notification link.

    0000055
    4.0K followersView on X

Explore more