Stored XSS Vulnerability in Flextype CMS by Flextype
CVE-2026-89145
2.4LOW
What is CVE-2026-89145?
Flextype CMS versions from 0.9.9 to 1.0.0-alpha.3 are vulnerable due to improper HTML escaping of plugin directory names on the dependency error page. This flaw enables attackers with write access to introduce a malicious plugin that contains HTML characters in its name. When dependency validation fails, this can lead to execution of arbitrary scripts in the browsers of users accessing the affected page. This presents a significant risk as it may lead to unauthorized access and manipulation of user sessions, ultimately compromising the security of the application.
Affected Version(s)
flextype 0.9.9 <= 1.0.0-alpha.3
