CVE-2026-71518
- EPSS 0.38%
- Veröffentlicht 17.08.2026 21:16:48
- Zuletzt bearbeitet 18.08.2026 15:17:01
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized pa...
CVE-2026-44401
- EPSS 0.22%
- Veröffentlicht 10.08.2026 19:29:40
- Zuletzt bearbeitet 11.08.2026 14:17:13
Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitized href value...
CVE-2026-71213
- EPSS 0.32%
- Veröffentlicht 05.08.2026 06:59:29
- Zuletzt bearbeitet 10.08.2026 12:17:25
Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited p...
CVE-2026-49133
- EPSS 0.34%
- Veröffentlicht 17.06.2026 20:39:47
- Zuletzt bearbeitet 14.07.2026 22:17:08
Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary files outside the content directory by supplying traversal sequences in the path query parameter passed ...
CVE-2026-24127
- EPSS 0.25%
- Veröffentlicht 23.01.2026 23:15:54
- Zuletzt bearbeitet 02.02.2026 13:32:53
Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoe...
CVE-2022-28053
- EPSS 1.19%
- Veröffentlicht 25.04.2022 13:15:49
- Zuletzt bearbeitet 21.11.2024 06:56:41
Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.