Stored HTML Attribute Injection Vulnerability in Typemill Content Management System
CVE-2026-53468

4.6MEDIUM

Key Information:

Vendor

Typemill

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-53468?

Typemill, a flat-file, Markdown-based content management system for documentation websites, is vulnerable to stored HTML attribute injection in the page metadata fields ('og:title' and 'og:description'). An authenticated user with permission to modify page metadata can exploit this flaw to inject arbitrary HTML attributes into generated tags. This vulnerability stems from a lack of proper output encoding, allowing for potential stored cross-site scripting (XSS) under certain browser or DOM interaction conditions. Users are advised to upgrade to version 2.23.0 to mitigate this risk.

Affected Version(s)

typemill < 2.23.0

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.