CVE-2026-71213: Typemill

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited password-guessing requests against any account, including administrators, with no throttling.

Affected products

  • Typemill Typemill: up to and including 2.25.0

Published 2026-08-05. Last modified 2026-08-26.