flextype vulnerability

Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers when dependency validation fails.

Published 11 Sep 2026Updated 11 Sep 20264 sources
CVSS 2.4

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.