Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-87930: Deserialization of Untrusted Data in MaxSite MaxSite CMSCVE-2026-87930
0

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist.

Join the discussion
CVE-2026-87929: Use of Hard-coded Cryptographic Key in MaxSite MaxSite CMSCVE-2026-87929
0

MaxSite CMS versions up to and including 109.6 contain a hardcoded session encryption key in the configuration file that is not changed during installation. This vulnerability allows unauthenticated attackers to forge administrator session cookies by computing an HMAC-SHA1 with the known key, bypassing authentication checks and gaining administrator privileges.

Join the discussion
CVE-2026-87928: Unrestricted Upload of File with Dangerous Type in MaxSite MaxSite CMSCVE-2026-87928
0

MaxSite CMS versions 0.94 through 109.6 have a vulnerability in the admin_page upload handler that allows logged-in users to upload HTML files. These files can contain malicious scripts that execute in visitors' browsers, enabling persistent stored cross-site scripting (XSS) attacks. The vulnerability arises from unrestricted upload of files with dangerous types to the uploads/_pages/ directory.

Join the discussion
CVE-2026-87927: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in MaxSite MaxSite CMSCVE-2026-87927
0

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/MaxSite CMS
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses