CVE Tools

CVE-2026-3395

MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection

No known exploitation. EPSS puts it in the 84th percentile. A vendor fix is available.

Published Updated Sources: CVE.org, NVD

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check your MaxSite CMS version and confirm whether you are running 109.1 or earlier (the fixed version is 109.2).
  2. If you are on 109.1 or earlier, upgrade MaxSite CMS to 109.2 as soon as possible.
  3. After upgrading, verify the site no longer serves the vulnerable preview-ajax.php behavior (confirm with your vendor/admin or staging test if you can).

What it is

From the CVE record

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 109.2 will fix this issue. This patch is called 08937a3c5d672a242d68f53e9fccf8a748820ef3. You should upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.

In plain language

Written by AI from the record

CVE-2026-3395 is a MaxSite CMS security hole that lets an attacker run malicious code on your server without needing a login; if you run MaxSite CMS up to 109.1, you should treat it as an urgent patch.

In MaxSite CMS, a vulnerable MarkItUp editor AJAX endpoint (preview-ajax.php) allows unauthenticated remote attackers to inject and execute arbitrary code via an eval-based flaw in the endpoint, enabling remote code execution without user interaction.

If you're affected

  • Full site and server compromise
  • Data theft from your CMS
  • Website defacement or downtime
  • Malware deployment on hosting

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS84th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

2.5% chance of exploitation activity in the next 30 days, which ranks it in the 84th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

6 events over 165 days, from the signal feeds we watch.

  1. Nuclei check added
  2. Patch availablerecord updated
  3. Publishedweakness classified, att&ck mapped

Affected products

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Scored 7.3 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality LowSome restricted information is disclosed, but limited in scope
  • Integrity LowData modification is possible but limited in scope or consequence
  • Availability LowReduced performance or intermittent disruption of service

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for CMS, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store