Sixapart / Movable Type
52 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-44392 | Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, uni… | MEDIUM | 5.3 | May 20, 2026 |
| CVE-2026-25776 | Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script. | CRITICAL | 9.3 | Apr 8, 2026 |
| CVE-2026-33088 | Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement. | MEDIUM | 6.9 | Apr 8, 2026 |
| CVE-2023-45746 | Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/versions are… | MEDIUM | 5.4 | Oct 30, 2023 |
| CVE-2022-45122 | Cross-site scripting vulnerability in Movable Type Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earlier (Movab… | MEDIUM | 6.1 | Dec 7, 2022 |
| CVE-2022-45113 | Improper validation of syntactic correctness of input vulnerability exist in Movable Type series. Having a user to access a specially crafted URL may allow a r… | MEDIUM | 6.5 | Dec 7, 2022 |
| CVE-2022-43660 | Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege of 'Manage… | HIGH | 7.2 | Dec 7, 2022 |
| CVE-2022-38078 | Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Ty… | CRITICAL | 9.8 | Aug 24, 2022 |
| CVE-2020-5669 | Cross-site scripting vulnerability in Movable Type Movable Type Premium 1.37 and earlier and Movable Type Premium Advanced 1.37 and earlier allows a remote aut… | MEDIUM | 5.4 | Oct 26, 2021 |
| CVE-2021-20837 | Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (… | CRITICAL | 9.8 | Oct 26, 2021 |
| CVE-2021-20815 | Cross-site scripting vulnerability in Edit Boilerplate screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 an… | MEDIUM | 6.1 | Aug 26, 2021 |
| CVE-2021-20814 | Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type… | MEDIUM | 6.1 | Aug 26, 2021 |
| CVE-2021-20813 | Cross-site scripting vulnerability in Edit screen of Content Data of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series) and Movable Type A… | MEDIUM | 6.1 | Aug 26, 2021 |
| CVE-2021-20812 | Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series… | MEDIUM | 6.1 | Aug 26, 2021 |
| CVE-2021-20811 | Cross-site scripting vulnerability in List of Assets screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and… | MEDIUM | 6.1 | Aug 26, 2021 |
| CVE-2021-20810 | Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0… | MEDIUM | 6.1 | Aug 26, 2021 |
| CVE-2021-20809 | Cross-site scripting vulnerability in Create screens of Entry, Page, and Content Type of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series… | MEDIUM | 6.1 | Aug 26, 2021 |
| CVE-2021-20808 | Cross-site scripting vulnerability in Search screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier… | MEDIUM | 6.1 | Aug 26, 2021 |
| CVE-2021-20665 | Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced… | MEDIUM | 6.1 | Mar 5, 2021 |
| CVE-2021-20664 | Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705… | MEDIUM | 6.1 | Mar 5, 2021 |
| CVE-2021-20663 | Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.… | MEDIUM | 6.1 | Mar 5, 2021 |
| CVE-2020-5577 | Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7),… | HIGH | 8.8 | May 14, 2020 |
| CVE-2020-5576 | Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4… | HIGH | 8.8 | May 14, 2020 |
| CVE-2020-5575 | Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) a… | MEDIUM | 6.1 | May 14, 2020 |
| CVE-2020-5574 | HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606… | MEDIUM | 5.3 | May 14, 2020 |
Showing 1 to 25 of 52 CVEs