Stored XSS Vulnerability in Flextype CMS by Flextype
CVE-2026-89145

2.4LOW

Key Information:

Vendor

Flextype

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89145?

Flextype CMS versions from 0.9.9 to 1.0.0-alpha.3 are vulnerable due to improper HTML escaping of plugin directory names on the dependency error page. This flaw enables attackers with write access to introduce a malicious plugin that contains HTML characters in its name. When dependency validation fails, this can lead to execution of arbitrary scripts in the browsers of users accessing the affected page. This presents a significant risk as it may lead to unauthorized access and manipulation of user sessions, ultimately compromising the security of the application.

Affected Version(s)

flextype 0.9.9 <= 1.0.0-alpha.3

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ali Khafagy
.