Medium severity6.1NVD Advisory· Published Feb 6, 2020· Updated Jun 17, 2026
CVE-2020-5528
CVE-2020-5528
Description
Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier (Movable Type 6.5), Movable Type Advanced 7 r.4603 and earlier (Movable Type Advanced 7), Movable Type Advanced 6.5.2 and earlier (Movable Type Advanced 6.5), Movable Type Premium 1.26 and earlier (Movable Type Premium), and Movable Type Premium Advanced 1.26 and earlier (Movable Type Premium Advanced)) allows remote attackers to inject arbitrary web script or HTML in the block editor and the rich text editor via a specially crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*:*range: >=6.5.0,<=6.5.2
- cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*range: <=1.26
- cpe:2.3:a:sixapart:movable_type:*:*:*:*:premium:*:*:*range: <=1.26
- (no CPE)range: <=r.4603 (Movable Type 7), <=6.5.2 (Movable Type 6.5), <=r.4603 (Movable Type Advanced 7), <=6.5.2 (Movable Type Advanced 6.5), <=1.26 (Movable Type Premium), <=1.26 (Movable Type Premium Advanced)
- Six Apart Ltd/Movable Type seriesv5Range: Movable Type 7 r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier (Movable Type 6.5), Movable Type Advanced 7 r.4603 and earlier (Movable Type Advanced 7), Movable Type Advanced 6.5.2 and earlier (Movable Type Advanced 6.5), Movable Type Premium 1.26 and earlier (Movable Type Premium), and Movable Type Premium Advanced 1.26 and earlier (Movable Type Premium Advanced)
Patches
Vulnerability mechanics
References
2- jvn.jp/en/jp/JVN94435544/index.htmlnvdThird Party Advisory
- movabletype.org/news/2020/02/movable_type_r4605_v720_v653_and_v6311_released.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.