CVE-2026-44401: Typemill

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitized href values in Markdown links. Attackers can craft Markdown links using the javascript: scheme through ParsedownExtension.php or TwigMarkdownExtension.php, storing a persistent payload that executes in the browser of every visitor who clicks the link, enabling session cookie theft, authenticated request forgery, and credential harvesting.

Affected products

  • Typemill Typemill: from 2.0.0, up to and including 2.23.0

Published 2026-08-10. Last modified 2026-09-10.