PT-2026-69931 · Unknown · Typemill Cms

·

CVE-2026-44401

·

Published

2026-08-10

·

Updated

2026-08-11

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Typemill CMS versions 2.x
Description A persistent cross-site scripting issue exists in the Markdown parser extension. Authenticated users with theme-configuration access can inject malicious JavaScript URIs by providing unsanitized href values in Markdown links. This is possible through ParsedownExtension.php or TwigMarkdownExtension.php by using the javascript: scheme. The stored payload executes in the browser of any visitor who clicks the link, which can lead to session cookie theft, authenticated request forgery, and credential harvesting.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44401

Affected Products

Typemill Cms