PatchSiren

typemill CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL typemill CVE published 2026-08-05

CVE-2026-71213

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) is vulnerable to unlimited password-guessing requests when captcha is disabled, which is the default configuration. This allows an unauthenticated attacker to send multiple requests against any account, including administrators, with no throttling. The vulnerability affects Typemill deployments with exposed login endpoints, especially [truncated]

HIGH typemill CVE published 2026-06-17

CVE-2026-49133

CVE-2026-49133 is a high-severity path traversal vulnerability in Typemill before 2.24.0. Authenticated attackers with Author-level privileges can read arbitrary files outside the content directory by manipulating the path query parameter. This vulnerability, with a CVSS score of 7.1, was publicly disclosed on June 17, 2026. The vulnerability was patched in version 2.24.2. Users should update to the lates [truncated]