Sploitus

CVE-2026-24127

No indexed exploits for CVE-2026-24127 yet

Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.

Affected products
Typemill
Typemill
< 2.19.2
Fix
Available
CVSS 3.1
6.1 MEDIUM
EPSS
0.3% (17th percentile)
Weakness
CWE-116, CWE-79
NVD status
Analyzed
Published
2026-01-23
CVE-2026-24127 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-24127 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-24127 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.