CVE-2026-70553 is an unauthenticated remote code execution vulnerability in MaxSite CMS affecting versions 105.2 through 109.5. The flaw resides in the install endpoint, which remains capable of processing crafted POST requests even after installation has completed. An attacker can supply a malicious value for the db_dbprefix parameter containing a single quote, causing application-generated PHP configuration content to break out of an intended string literal in the database configuration file and append attacker-controlled PHP statements. Because the injected code is written into the application's configuration and subsequently interpreted by PHP during normal application execution, the payload is executed on later requests, yielding persistent server-side code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone Python PoC for CVE-2026-70553 affecting MaxSite CMS. Structure is minimal: one executable script (exploit.py), English and Chinese READMEs, and a license. The exploit is not framework-based. The Python script uses requests to interact with a target MaxSite CMS instance over HTTP. It first checks whether the installer endpoint /install/ is reachable and appears to be an active installation page rather than an already-completed install. If reachable, it submits a crafted POST request to the installer with attacker-controlled form fields. The key malicious field is db_dbprefix, which is set to a string that closes the expected PHP string literal, injects arbitrary PHP code, and comments out the remainder. This causes the installer to write attacker code into application/config/database.php, creating persistent server-side code execution because that file is loaded on subsequent requests. Main capabilities: - Reachability check for the installer endpoint - Unauthenticated exploitation via POST to /install/ - Persistent PHP code injection into database.php - Optional verification by requesting a proof file created by the default payload - Support for custom PHP payloads via --cmd, including command execution, reverse shell, or webshell dropper behavior The default payload is operational rather than just demonstrative: it writes poc_test.txt to confirm code execution. The script also supports arbitrary custom PHP, making it capable of broader post-exploitation if the vulnerable conditions are met. However, the repository itself repeatedly documents an important limitation: exploitation only works when the install endpoint is still exposed and the database tables do not yet exist, such as on fresh or interrupted installations. As a result, this is a real exploit PoC with practical constraints, not merely a detector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.