Description
Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers when dependency validation fails.
Published: 2026-09-11
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw in Flextype CMS versions 0.9.9 through 1.0.0‑alpha.3. Due to insufficient HTML escaping of plugin directory names, an attacker who can write to the plugins directory can create a plugin whose name contains malicious scripts. plugin dependency, it renders a raw directory name, causing the browser to execute the attacker‑supplied code. This results in arbitrary script execution in the browsers of users who view the error page, potentially enabling session hijacking or other client‑side attacks. The flaw represents a client‑side injection weakness identified as CWE‑79.

Affected Systems

Flextype CMS versions 0.9.9 through 1.0.0‑alpha.3 hosted on any web server environment that permits users to write to the files or directories used for plugins. The flaw is present wherever the getValidPluginsDependencies() function runs and renders an unescaped dependency error. All installations of Flextype CMS containing the vulnerable code are affected, regardless of the presence of other plugins.

Risk and Exploitability

The CVSS score of 2.4 indicates low severity. No EPSS score is provided, so the current exploitation probability is unknown but likely limited to environments where an attacker has file‑write access to the plugins directory. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires the ability to create or rename a plugin directory so that the dependency validation error occurs; this usually means the attacker needs administrative or privileged access to the file system. Therefore, while the technical impact is low, the risk rises if reasonable safeguards for plugin directory write permissions are not in place.

Generated by OpenCVE AI on September 11, 2026 at 03:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Flextype CMS to a fixed version where plugin directory names are HTML‑escaped in dependency error pages.
  • Restrict write access to the plugins directory to trusted administrators only and remove write permissions for untrusted users.
  • Remove or rename any plugin directories whose names contain HTML or JavaScript characters to eliminate the trigger for the injected code.

Generated by OpenCVE AI on September 11, 2026 at 03:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Flextype
Flextype flextype
Vendors & Products Flextype
Flextype flextype

Fri, 11 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers when dependency validation fails.
Title Flextype CMS 0.9.9 through 1.0.0-alpha.3 Stored XSS via Plugin Directory
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Flextype Flextype
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T14:25:37.980Z

Reserved: 2026-09-11T01:04:51.012Z

Link: CVE-2026-89145

cve-icon Vulnrichment

Updated: 2026-09-11T14:25:34.669Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T02:18:35.617

Modified: 2026-09-24T20:43:32.537

Link: CVE-2026-89145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:00:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')