CVE-2026-89145
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-79
Neutralización incorrecta de la entrada durante la generación de la página web (Cross-site Scripting)
Fecha de publicación:
11/09/2026
Última modificación:
24/09/2026
Descripción
*** Pendiente de traducción *** Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers when dependency validation fails.
Impacto
Puntuación base 4.0
2.40
Gravedad 4.0
BAJA
Puntuación base 3.x
4.20
Gravedad 3.x
MEDIA
Referencias a soluciones, herramientas e información
- https://github.com/flextype/flextype
- https://github.com/flextype/flextype/blob/aea4ead8c449ea5517ed53b6dcbd28b0a528ad9d/src/flextype/core/Plugins.php#L345
- https://github.com/flextype/flextype/issues/597
- https://www.vulncheck.com/advisories/flextype-cms-0.9.9-through-1.0.0-alpha.3-stored-xss-via-plugin-directory


