typemill CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

typemill vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to typemill, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-24127 Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2. [email protected] 5.4 0.06% 2026-01-23 2026-02-02
CVE-2022-28053 Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. [email protected] 8.8 0.78% 2022-04-25 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence