CVE-2026-32986 MEDIUM

CVE-2026-32986: Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection

Vendor Textpattern
Product Textpattern CMS
Weakness CWE-79 · XSS
Published March 20, 2026
Last update March 20, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting improper sanitization of user-supplied input in Atom feed XML elements. Attackers can embed unescaped payloads in parameters such as category that are reflected into Atom fields like and , which execute as JavaScript when feed readers or CMS aggregators consume the feed and insert content into the DOM using unsafe methods.

Key dates

02Disclosure timeline

March 20, 2026 CVE published
March 20, 2026 Record updated