Home MaxSite CVE-2026-3395
Back to MaxSite

CVE-2026-3395

MaxSite CMS - MarkItUp Preview AJAX Endpoint

MaxSite CVSS 7.3 Updated April 6, 2026

Executive Risk Summary

"A code injection vulnerability has been discovered in the MarkItUp Preview AJAX Endpoint of MaxSite CMS, allowing remote attackers to execute malicious code. Upgrading to version 109.2, specifically applying patch 08937a3c5d672a242d68f53e9fccf8a748820ef3, will resolve this issue."

Anticipated Attack Path

  1. 1. Initial Exploitation: Attacker sends malicious request to the MarkItUp Preview AJAX Endpoint
  2. 2. Code Injection: Malicious code is injected into the endpoint, allowing for potential system compromise
  3. 3. Post-Exploitation: Attacker may use the injected code to further exploit the system or steal sensitive data

Am I Vulnerable?

  • Verify the version of MaxSite CMS and MarkItUp Preview AJAX Endpoint
  • Check for any suspicious activity or logs related to the endpoint
  • Apply the patch 08937a3c5d672a242d68f53e9fccf8a748820ef3 to resolve the vulnerability

Operational Audit Arsenal

Target Type PHP File
Target Asset preview-ajax.php
Standard Path application/maxsite/admin/plugins/editor_markitup/

Manual Verification Required

This is a non-Windows asset (MaxSite). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Unlikely

Minimal, as the patch only updates the MarkItUp Preview AJAX Endpoint

Internal Work Notes

Urgent: MaxSite CMS MarkItUp Preview AJAX Endpoint code injection vulnerability - upgrade to version 109.2 and apply patch 08937a3c5d672a242d68f53e9fccf8a748820ef3 to prevent potential system compromise.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.