Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers when dependency validation fails. | |
| Title | Flextype CMS 0.9.9 through 1.0.0-alpha.3 Stored XSS via Plugin Directory | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T01:14:20.554Z
Reserved: 2026-09-11T01:04:51.012Z
Link: CVE-2026-89145
No data.
Status : Received
Published: 2026-09-11T02:18:35.617
Modified: 2026-09-11T02:18:35.617
Link: CVE-2026-89145
No data.
OpenCVE Enrichment
Updated: 2026-09-11T03:30:16Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')