CVE-2026-7015Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 109.4 is capable of addressing this issue. The name of the patch is 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7. It is suggested to upgrade the affected component. The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via `htmlspecialchars()` has already been fixed in the latest patch to prevent incorrect data display."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-26: 3Technical Details · 2026-04-26: 104-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7015 A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argume… https://www.cve.org/CVERecord?id=CVE-2026-7015

    Post summary

    CVE‑2026‑7015 is reported as a vulnerability in MaxSite CMS up to 109.3 affecting the Guestbook Plugin, with minimal technical details and no evidence of exploitation or remediation.

    00000138
    57.3K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7015 📊 Severity: 2.4 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7015 #CVE-2026-7015 #CVE #Low #CyberSecurity #InfoSec https://t.co/WNcaFwYcAw

    Post summary

    The tweet announces the discovery of CVE-2026-7015, notes its low severity, and provides a link to the NVD page, but offers no technical, exploit, or mitigation details.

    0000042
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7015 Cross-Site Scripting in MaxSite CMS Guestbook Plugin Up to 109.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7015

    Post summary

    The text announces CVE‑2026‑7015, a cross‑site scripting vulnerability in the MaxSite CMS Guestbook plugin up to version 109.3, with a link to a vulnerability details page but no additional exploitation or patch information.

    0000041
    4.0K followersView on X

Explore more