PT-2026-4535 · Typemill · Typemill

Adrien Brunner

·

Published

2026-01-23

·

Updated

2026-02-02

·

CVE-2026-24127

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Typemill versions 2.19.1 and below
Description Typemill is a flat-file, Markdown-based CMS for informational documentation websites. A reflected Cross-Site Scripting (XSS) issue exists in the login error view template login.twig. The username value is echoed back without proper encoding when authentication fails, allowing an attacker to execute script in the login page context.
Recommendations Update to version 2.19.2 or later.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-24127
GHSA-65X4-PJHJ-R8WR

Affected Products

Typemill