Skip to content

Submit #762169: maxsite CMS CMS 109.1 Code Injection

Vuldb March 1, 2026

Attacker-controlled input sent to the MarkItUp preview AJAX endpoint is passed through content hooks and reaches `eval()` in `run_php`, enabling ...

Extracted Entities