VYPR

maxsite-cve4

by EviL0rd

CVEs (1)

  • CVE-2026-87929CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.00

    MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with…