Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Movable Type CRITICAL 9.8
CVE-2026-33088

Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.

Fix: 8.0.10 / 8.8.3+
Fix from $2,300 2026-04-08
Movable Type CRITICAL 9.8
CVE-2026-25776

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

Fix: 8.0.10 / 8.8.3+
Fix from $2,300 2026-04-08
Movable Type MEDIUM 5.4
CVE-2023-45746

Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/ver…

Fix: 1.59 / 7.902.0+
Fix from $1,600 2023-10-30
Movable Type MEDIUM 6.5
CVE-2022-45113

Improper validation of syntactic correctness of input vulnerability exist in Movable Type series. Having a user to access a specially crafted URL may…

Fix: 6.8.7 / 7.9.6+
Fix from $1,600 2022-12-07
Movable Type MEDIUM 6.1
CVE-2022-45122

Cross-site scripting vulnerability in Movable Type Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earl…

Fix: 6.8.7 / 7.9.6+
Fix from $1,600 2022-12-07
Movable Type HIGH 7.2
CVE-2022-43660

Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege …

Fix: 7.9.6+
Fix from $1,950 2022-12-07
Movable Type CRITICAL 9.8
CVE-2022-38078

Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to …

Fix: 1.53 / 6.8.7+
Fix from $2,300 2022-08-24
Movable Type MEDIUM 5.4
CVE-2020-5669

Cross-site scripting vulnerability in Movable Type Movable Type Premium 1.37 and earlier and Movable Type Premium Advanced 1.37 and earlier allows a …

Fix: after 1.37
Fix from $1,600 2021-10-26
Movable Type CRITICAL 9.8
CVE-2021-20837EPSS 88%

Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and…

Fix: after 7.8.1
Fix from $2,300 2021-10-26
Movable Type MEDIUM 6.1
CVE-2021-20808

Cross-site scripting vulnerability in Search screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 an…

Fix: 7.8.0+
Fix from $1,600 2021-08-26
Movable Type MEDIUM 6.1
CVE-2021-20809

Cross-site scripting vulnerability in Create screens of Entry, Page, and Content Type of Movable Type (Movable Type 7 r.4903 and earlier (Movable Typ…

Fix: 7.8.0+
Fix from $1,600 2021-08-26
Movable Type MEDIUM 6.1
CVE-2021-20810

Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable T…

Fix: 7.8.0+
Fix from $1,600 2021-08-26
Movable Type MEDIUM 6.1
CVE-2021-20811

Cross-site scripting vulnerability in List of Assets screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type …

Fix: 7.8.0+
Fix from $1,600 2021-08-26
Movable Type MEDIUM 6.1
CVE-2021-20812

Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Type Advance…

Fix: 7.8.0+
Fix from $1,600 2021-08-26
Movable Type MEDIUM 6.1
CVE-2021-20813

Cross-site scripting vulnerability in Edit screen of Content Data of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series) and Mova…

Fix: 7.8.0+
Fix from $1,600 2021-08-26
Movable Type MEDIUM 6.1
CVE-2021-20814

Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and earlier (Mov…

Fix: 7.8.0+
Fix from $1,600 2021-08-26
Movable Type MEDIUM 6.1
CVE-2021-20815

Cross-site scripting vulnerability in Edit Boilerplate screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Typ…

Fix: 7.8.0+
Fix from $1,600 2021-08-26
Movable Type HIGH 8.8
CVE-2020-5576

Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Adva…

Fix: after 7.2.1
Fix from $1,950 2020-05-14
Movable Type HIGH 8.8
CVE-2020-5577

Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Adv…

Fix: after 7.2.1
Fix from $1,950 2020-05-14
Movable Type MEDIUM 6.1
CVE-2020-5575

Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606…

Fix: after 7.2.1
Fix from $1,600 2020-05-14
Movable Type MEDIUM 5.3
CVE-2020-5574

HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advance…

Fix: after 7.2.1
Fix from $1,600 2020-05-14
Movable Type MEDIUM 6.1
CVE-2020-5528

Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier (Movabl…

Fix: after 7.1.4
Fix from $1,600 2020-02-06
Movable Type MEDIUM 6.1
CVE-2019-6025

Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable …

Fix: after 7.1.3
Fix from $1,600 2019-12-26
Movable Type MEDIUM 6.1
CVE-2018-0672

Cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1 allows remote attackers to inject arbitrary web script or HTML via un…

Fix: 6.3.1+
Fix from $1,600 2018-09-04
Movable Type CRITICAL 9.8
CVE-2016-5742

SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open S…

Fix: after 5.2.13
Fix from $2,300 2017-01-23
Movabletype HIGH 7.5
CVE-2015-0845

Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attack…

Fix: after 5.2.11
Fix from $1,950 2015-04-17
Movable Type HIGH 7.5
CVE-2013-2184

Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_…

Fix: after 5.2.5
Fix from $1,950 2015-03-27
Movable Type HIGH 7.5
CVE-2013-0209EPSS 45%

lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration fun…

Patch available
Fix from $1,950 2013-01-23
Movable Type HIGH 7.5
CVE-2011-5085

Unspecified vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to read or modify data via unknown vectors.

Patch available
Fix from $1,950 2012-04-02
Movable Type HIGH 7.5
CVE-2012-0320

Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectors related …

Fix: after 4.37
Fix from $1,950 2012-03-03