PatchSiren

typemill CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH typemill CVE published 2026-08-17

CVE-2026-71518

CVE-2026-71518 is an authorization bypass vulnerability in Typemill before version 2.26.0. The vulnerability allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. This could lead to unauthorized file downloads without credentials. The vulnerability exists in the media file download route of Typemill, allowing attackers to bypass authorization checks by sub [truncated]

MEDIUM Typemill CVE published 2026-08-10

CVE-2026-44401

CVE-2026-44401 is a persistent cross-site scripting vulnerability in Typemill CMS version 2.x. Authenticated users with theme-configuration access can inject malicious JavaScript URIs through Markdown links, allowing for session cookie theft, authenticated request forgery, and credential harvesting. The vulnerability exists in the Markdown parser extension, enabling attackers to craft malicious links. Def [truncated]

CRITICAL typemill CVE published 2026-08-05

CVE-2026-71213

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) is vulnerable to unlimited password-guessing requests when captcha is disabled, which is the default configuration. This allows an unauthenticated attacker to send multiple requests against any account, including administrators, with no throttling. The vulnerability affects Typemill deployments with exposed login endpoints, especially [truncated]

HIGH typemill CVE published 2026-06-17

CVE-2026-49133

CVE-2026-49133 is a high-severity path traversal vulnerability in Typemill before 2.24.0. Authenticated attackers with Author-level privileges can read arbitrary files outside the content directory by manipulating the path query parameter. This vulnerability, with a CVSS score of 7.1, was publicly disclosed on June 17, 2026. The vulnerability was patched in version 2.24.2. Users should update to the lates [truncated]