Typemill is a modestly represented flat-file content-management and static-site-generator platform with a narrow product footprint focused on its core publishing application. The durable signal centers on output-encoding and input-sanitization issues, specifically improper escaping of web-generated content, cross-site scripting, and unrestricted file upload vulnerabilities that reflect typical attack surfaces in web-facing publishing and templating systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Typemill over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49133MEDIUM Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary files outside the content director | Jun 17, 2026 | 6.5 | 28 | NO | NO |
CVE-2022-28053HIGH Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafte | Apr 25, 2022 | 8.8 | 27 | NO | NO |
CVE-2026-24127MEDIUM Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login | Jan 23, 2026 | 6.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Typemill.
Media articles that mention a CVE ID that affects a product developed by Typemill — matched by CVE ID, not by vendor name.