Vendor
critical
advisory
Unauthenticated Remote Code Execution in MaxSite CMS via Config Injection
1 rule 1 TTP 3 CVEs 1 IOCMaxSite CMS is vulnerable to remote code execution due to improper input sanitization of the db_dbprefix parameter, allowing unauthenticated attackers to inject persistent PHP code into the database configuration file.
PoC
MaxSite CMS +2
web-application
cms
vulnerability
1r
1t
3c
1i
updated
critical
threat
iCagenda Unrestricted File Upload Vulnerability Leading to RCE (CVE-2026-48939)
1 rule 2 TTPs 5 CVEs 7 IOCsAttackers are actively exploiting CVE-2026-48939, an unrestricted file upload vulnerability in iCagenda, to upload malicious PHP code and achieve remote code execution on affected web servers.
exploited
PoC
iCagenda +19
web-application
rce
file-upload
cve
1r
2t
5c
7i
updated