CVE 5.4 MEDIUM

Typemill has Reflected XSS via login error view template_CVE-2026-24127

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Description

Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.

Basic Information

ID CVE-2026-24127
Source GitHub_M
Published Jan 23, 2026 at 23:01

Affected Product

Vendor typemill
Product typemill
Version < v2.19.2
Affected Versions typemill typemill < v2.19.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.