CVE-2026-7016Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used. Upgrading to version 109.4 is recommended to address this issue. The patch is named 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7. Upgrading the affected component is recommended. The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via `htmlspecialchars()` has already been fixed in the latest patch to prevent incorrect data display."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-26: 3Technical Details · 2026-04-26: 104-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7016 A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_n… https://www.cve.org/CVERecord?id=CVE-2026-7016

    Post summary

    The text briefly announces CVE-2026-7016, a vulnerability in the Ushki plugin of MaxSite CMS involving manipulation of an argument, but it lacks detailed technical data, PoC, or mitigation information.

    00000131
    57.3K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7016 📊 Severity: 2.4 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7016 #CVE-2026-7016 #CVE #Low #CyberSecurity #InfoSec https://t.co/RTdZWOLc1E

    Post summary

    The tweet is a low‑severity CVE alert that merely references the NVD entry without providing technical details, exploitation evidence, or patch information.

    0000049
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7016 Cross-Site Scripting in MaxSite CMS ushki Plugin Up to Version 109.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7016

    Post summary

    The note provides an initial disclosure of CVE‑2026‑7016, a Cross‑Site Scripting flaw affecting the MaxSite CMS ushki plugin up to version 109.3.

    0000040
    4.0K followersView on X

Explore more