Typemill

Typemill

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 17.08.2026 21:16:48
  • Zuletzt bearbeitet 18.08.2026 15:17:01

Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized pa...

  • EPSS 0.22%
  • Veröffentlicht 10.08.2026 19:29:40
  • Zuletzt bearbeitet 11.08.2026 14:17:13

Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitized href value...

  • EPSS 0.32%
  • Veröffentlicht 05.08.2026 06:59:29
  • Zuletzt bearbeitet 10.08.2026 12:17:25

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited p...

  • EPSS 0.34%
  • Veröffentlicht 17.06.2026 20:39:47
  • Zuletzt bearbeitet 14.07.2026 22:17:08

Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary files outside the content directory by supplying traversal sequences in the path query parameter passed ...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 23.01.2026 23:15:54
  • Zuletzt bearbeitet 02.02.2026 13:32:53

Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoe...

Exploit
  • EPSS 1.19%
  • Veröffentlicht 25.04.2022 13:15:49
  • Zuletzt bearbeitet 21.11.2024 06:56:41

Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.