Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting improper sanitization of user-supplied input in Atom feed XML elements. Attackers can embed unescaped payloads in parameters such as category that are reflected into Atom fields like and , which execute as JavaScript when feed readers or CMS aggregators consume the feed and insert content into the DOM using unsafe methods.
References
| Link | Resource |
|---|---|
| https://packetstorm.news/files/id/216241/ | Exploit Issue Tracking |
| https://textpattern.com/ | Product |
Configurations
History
16 Apr 2026, 14:44
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:textpattern:textpattern:4.9.0:-:*:*:*:*:*:* | |
| First Time |
Textpattern textpattern
Textpattern |
|
| References | () https://packetstorm.news/files/id/216241/ - Exploit, Issue Tracking | |
| References | () https://textpattern.com/ - Product |
20 Mar 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting improper sanitization of user-supplied input in Atom feed XML elements. Attackers can embed unescaped payloads in parameters such as category that are reflected into Atom fields like and , which execute as JavaScript when feed readers or CMS aggregators consume the feed and insert content into the DOM using unsafe methods. |
20 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-20 16:16
Updated : 2026-04-16 14:44
NVD link : CVE-2026-32986
Mitre link : CVE-2026-32986
CVE.ORG link : CVE-2026-32986
JSON object : View
Products Affected
textpattern
- textpattern
