CVE-2026-87929 | MaxSite CMS up to 109.6 Session Management config.php is_login hard-coded key

SecurityVulns

A vulnerability classified as critical was found in MaxSite CMS up to 109.6. Affected by this issue is the function is_login of the file application/config/config.php of the component Session Management. Executing a manipulation can lead to use of hard-coded cryptographic key
. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is tracked as CVE-2026-87929. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More