CVE-2026-53468
The CVE Severity Digest turns the National Vulnerability Database feed into a prioritized security briefing. It groups affected software into practical product families, distinguishes patch and mitigation references from general citations, and ranks the vulnerabilities most likely to matter to technology operators while preserving direct links to the official record.
- CVE
- CVE-2026-53468
- Description
- Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Versions prior to 2.23.0 are vulnerable to stored HTML attribute injection in the page metadata fields (`og:title` and `og:description`). An authenticated user with permission to modify page metadata can inject arbitrary HTML attributes into generated `<meta>` tags due to missing output encoding. Under certain browser or DOM interaction scenarios, this may lead to stored cross-site scripting (XSS). Version 2.23.0 fixes the issue.
- Published
- 08/21/2026
- Severity
- MEDIUM
- CVSS
- 4.6
- Priority score
- 48.752