Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53468— Typemill has Stored HTML Attribute Injection in Metadata Fields

Quick assessment

Affected
typemill typemill
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Typemill 是一个基于 Markdown 的扁平文件内容管理系统,专为信息文档类网站而设计。在 2.23.0 版本之前的 Typemill 存在存储型 HTML 属性注入漏洞,该漏洞影响页面元数据字段( 和 )。具有修改页面元数据权限的已认证用户,由于缺少输出编码,可以向生成的 标签中注入任意的 HTML 属性。在某些浏览器或 DOM 交互场景下,这可能导致存储型跨站脚本(XSS)攻击。2.23.0 版本修复了该问题。

CVSS 4.6 · Medium EPSS 0.17% · P6

Affected Version Matrix 1

VendorProduct Version RangeStatus
typemill typemill < 2.23.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53468

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Typemill has Stored HTML Attribute Injection in Metadata Fields
Source: CVE Program / CVE List V5
Vulnerability Description
Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Versions prior to 2.23.0 are vulnerable to stored HTML attribute injection in the page metadata fields (`og:title` and `og:description`). An authenticated user with permission to modify page metadata can inject arbitrary HTML attributes into generated `<meta>` tags due to missing output encoding. Under certain browser or DOM interaction scenarios, this may lead to stored cross-site scripting (XSS). Version 2.23.0 fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
typemill typemill < 2.23.0 -

II. Public POCs for CVE-2026-53468

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53468

登录查看更多情报信息。

Vendor Advisories for CVE-2026-53468 (1)

Vendor Pages for CVE-2026-53468 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53468

No comments yet


Leave a comment