Junglewise Threat Intelligence

CVE-2026-89145: Flextype CMS stored XSS via plugin directory names

CVE-2026-89145 · Severity: medium · CVSS 4.2 · Published 2026-09-11

Executive brief

Flextype is an open-source flat-file content management system. A cross-site scripting (XSS) vulnerability allows attackers who can write to the plugins directory to craft malicious plugin folder names containing HTML/JavaScript code. When the system displays a dependency validation error, the unescaped plugin name is rendered in the browser, executing the attacker's script in the context of any user viewing the error page.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the getValidPluginsDependencies() function, which renders plugin directory names in dependency error pages without proper HTML escaping. The vulnerable component is the plugin dependency validation logic in Flextype versions 0.9.9 through 1.0.0-alpha.3. Attack requires write access to the plugins directory (local or via a prior compromise), and the XSS is triggered when any admin or user views the dependency error page. An attacker can execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking, credential theft, or malicious redirects. The fix involves sanitizing or HTML-escaping plugin directory names before rendering them in the error page output.

Affected products

  • Flextype Flextype 0.9.9 through 1.0.0-alpha.3

Timeline

  • 2026-09-11: disclosed

References

Related threats