flextype

4 known vulnerabilities in flextype, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-91751 CVSS 7.2 high Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders…
  • CVE-2026-89145 CVSS 2.4 low Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by…
  • CVE-2026-88897 CVSS 8.2 high Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes…
  • CVE-2026-77939 CVSS 7.1 high Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid…