Reflected Cross-Site Scripting in Typemill CMS by Typemill
CVE-2026-24127
5.4MEDIUM
What is CVE-2026-24127?
Typemill is a flat-file, Markdown-based Content Management System (CMS) tailored for designing informational documentation websites. A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the login error view template, specifically in login.twig, affecting versions 2.19.1 and earlier. When authentication fails, the username input can be echoed back unvalidated, allowing an attacker to inject and execute malicious scripts in the context of the login page. This security flaw has been addressed in version 2.19.2, which remedied the improper contextual encoding.
Affected Version(s)
typemill < v2.19.2
