CVE-2026-7013General

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 109.4 can resolve this issue. The identifier of the patch is 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7. It is advisable to upgrade the affected component. The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via `htmlspecialchars()` has already been fixed in the latest patch to prevent incorrect data display."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-26: 3Technical Details · 2026-04-26: 104-26
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-7013 A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manip… https://www.cve.org/CVERecord?id=CVE-2026-7013

    Post summary

    The post announces the detection of CVE‑2026‑7013 in MaxSite CMS but provides no additional technical details, PoC, or actionable information.

    00000160
    57.3K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7013 📊 Severity: 2.4 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7013 #CVE-2026-7013 #CVE #Low #CyberSecurity #InfoSec https://t.co/J4mfiMgsDm

    Post summary

    The tweet announces CVE‑2026‑7013 with a low severity rating of 2.4, but provides no additional technical, exploit, or mitigation details.

    0000044
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7013 Cross Site Scripting in MaxSite CMS Mail_send Plugin Up To 109.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7013

    Post summary

    The entry announces a new XSS vulnerability in the MaxSite CMS Mail_send plugin, offering limited technical details and a link for more information, but provides no PoC, exploit, or mitigation guidance.

    0000055
    4.0K followersView on X

Explore more