Security Advisory

CVE-2026-24127

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-01-23 23:01:15
Last updated 2026-01-26 16:18:10
Assigner GitHub_M
CVSS score 5.4
State PUBLISHED

Description

Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.