Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting improper sanitization of user-supplied input in Atom feed XML elements. Attackers can embed unescaped payloads in parameters such as category that are reflected into Atom fields like and , which execute as JavaScript when feed readers or CMS aggregators consume the feed and insert content into the DOM using unsafe methods.
References
| Link | Resource |
|---|---|
| https://packetstorm.news/files/id/216241/ | Exploit Issue Tracking |
| https://textpattern.com/ | Product |
Configurations
History
No history.
Information
Published : 2026-03-20 16:16
Updated : 2026-06-17 10:36
NVD link : CVE-2026-32986
Mitre link : CVE-2026-32986
CVE.ORG link : CVE-2026-32986
JSON object : View
Products Affected
textpattern
- textpattern
