CVE-2020-35126: Typesettercms Typesetter

Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the significance of this report is disputed because "admins are considered trustworthy.

Affected products

Published 2020-12-11. Last modified 2026-06-17.