CVE-2026-70552 | MaxSite CMS up to 109.5 AJAX Dispatcher ajax.php X-Requested-With state issue

SecurityVulns

A vulnerability has been found in MaxSite CMS up to 109.5 and classified as critical. The affected element is an unknown function of the file ajax.php of the component AJAX Dispatcher. Performing a manipulation of the argument X-Requested-With results in state issue.

This vulnerability is identified as CVE-2026-70552. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More