Sixapart / Movabletype
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2015-0845 | Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to exe… | HIGH | 7.5 | Apr 17, 2015 |
| CVE-2014-5313 | Cross-site scripting (XSS) vulnerability in the management page in Six Apart Movable Type before 5.2 allows remote authenticated users to inject arbitrary web… | LOW | 3.5 | Sep 10, 2014 |
| CVE-2014-0977 | Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5.2.9, and 6.0.x before 6.0.1 allows rem… | MEDIUM | 4.3 | Jan 10, 2014 |
| CVE-2010-4511 | Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic publishing error me… | HIGH | 10.0 | Dec 9, 2010 |
| CVE-2010-4509 | Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to the (1) mt:AssetProp… | HIGH | 10.0 | Dec 9, 2010 |
| CVE-2010-3922 | SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands via unspecified vecto… | HIGH | 7.5 | Dec 9, 2010 |
| CVE-2010-3921 | Cross-site scripting (XSS) vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to inject arbitrary web script or HTML via… | MEDIUM | 4.3 | Dec 9, 2010 |
Showing 1 to 7 of 7 CVEs