Junglewise Threat Intelligence

CVE-2025-71164: Typesetter CMS reflected XSS in Editing component

CVE-2025-71164 · Severity: medium · CVSS 5.4 · Published 2026-01-14

Technologies: Typesetter CMS, Typesettercms Typesetter. Vendors: Typesetter, Typesettercms.

Executive brief

Typesetter CMS, a content management system used for website editing, contains a security flaw in its editing component. An attacker with basic editing permissions could trick another user into executing malicious code in their web browser. This could lead to unauthorized access to sensitive information or the hijacking of user sessions.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Typesetter CMS versions <= 5.1 within the include/tool/Editing.php file. The vulnerability is caused by the 'images' parameter (submitted as images[] in a POST request) being reflected into an HTML href attribute without proper context-aware output encoding. An authenticated attacker with editing privileges can exploit this by supplying a JavaScript pseudo-protocol (e.g., javascript:). Successful exploitation requires user interaction and allows for arbitrary JavaScript execution in the victim's browser session. As of the advisory date, the project appears to be unmaintained, and no official patch has been confirmed.

Affected products

  • Typesetter Typesetter CMS up to and including 5.1

Timeline

  • 2025-03-09: disclosed: Issue reported on GitHub repository
  • 2026-01-14: advisory: NVD and VulnCheck advisory published

References

Related threats