Reflected Cross-Site Scripting in Typemill CMS by Typemill
CVE-2026-24127

5.4MEDIUM

Key Information:

Vendor

Typemill

Status
Vendor
CVE Published:
23 January 2026

What is CVE-2026-24127?

Typemill is a flat-file, Markdown-based Content Management System (CMS) tailored for designing informational documentation websites. A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the login error view template, specifically in login.twig, affecting versions 2.19.1 and earlier. When authentication fails, the username input can be echoed back unvalidated, allowing an attacker to inject and execute malicious scripts in the context of the login page. This security flaw has been addressed in version 2.19.2, which remedied the improper contextual encoding.

Affected Version(s)

typemill < v2.19.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.