Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users… (CVE-2026-44401)
Typemill CMS version 2.x has a persistent cross-site scripting (XSS) vulnerability in its Markdown parser extension. Authenticated users with theme-configuration access can inject malicious JavaScript URIs via unsanitized href values in Markdown links. This allows attackers to store persistent payloads that execute in the browsers of visitors who click the crafted links, potentially leading to session cookie theft, request forgery, and credential harvesting.
AI Analysis
Technical Summary
Typemill CMS 2.x contains a persistent XSS vulnerability (CVE-2026-44401) in the Markdown parser extension. Authenticated users with theme-configuration privileges can supply unsanitized href attributes in Markdown links, including javascript: scheme URIs, through ParsedownExtension.php or TwigMarkdownExtension.php. This results in persistent malicious JavaScript being stored and executed in the browsers of users who click the links, enabling theft of session cookies, authenticated request forgery, and credential harvesting.
Potential Impact
The vulnerability allows attackers with authenticated theme-configuration access to inject persistent malicious JavaScript code that executes in the context of users visiting the affected site. This can lead to session cookie theft, forged authenticated requests, and harvesting of user credentials. The CVSS score is 4.8 (medium severity), reflecting the need for authentication and user interaction for exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict theme-configuration access to trusted users only and avoid clicking suspicious Markdown links. Monitor vendor channels for updates and apply official patches once released.
Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users… (CVE-2026-44401)
Description
Typemill CMS version 2.x has a persistent cross-site scripting (XSS) vulnerability in its Markdown parser extension. Authenticated users with theme-configuration access can inject malicious JavaScript URIs via unsanitized href values in Markdown links. This allows attackers to store persistent payloads that execute in the browsers of visitors who click the crafted links, potentially leading to session cookie theft, request forgery, and credential harvesting.
CVSS v3.1
Score 4.8medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Typemill CMS 2.x contains a persistent XSS vulnerability (CVE-2026-44401) in the Markdown parser extension. Authenticated users with theme-configuration privileges can supply unsanitized href attributes in Markdown links, including javascript: scheme URIs, through ParsedownExtension.php or TwigMarkdownExtension.php. This results in persistent malicious JavaScript being stored and executed in the browsers of users who click the links, enabling theft of session cookies, authenticated request forgery, and credential harvesting.
Potential Impact
The vulnerability allows attackers with authenticated theme-configuration access to inject persistent malicious JavaScript code that executes in the context of users visiting the affected site. This can lead to session cookie theft, forged authenticated requests, and harvesting of user credentials. The CVSS score is 4.8 (medium severity), reflecting the need for authentication and user interaction for exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict theme-configuration access to trusted users only and avoid clicking suspicious Markdown links. Monitor vendor channels for updates and apply official patches once released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8vfw-vh7q-p649
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-44401"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7b6fd2bf8831d5393ea59c
Added to database: 08/11/2026, 18:54:10 UTC
Last enriched: 08/11/2026, 19:12:41 UTC
Last updated: 08/12/2026, 00:41:12 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.