VYPR
Medium severity4.8NVD Advisory· Published Oct 23, 2025· Updated Apr 15, 2026

CVE-2025-54856

CVE-2025-54856

Description

Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit ContentData page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Movable Type contains a stored XSS vulnerability in the Edit ContentData page, allowing attackers with ContentType Management privilege to execute arbitrary scripts.

Vulnerability

Description Movable Type's Edit ContentData page suffers from a stored cross-site scripting (XSS) vulnerability due to insufficient input sanitization. An attacker with the "ContentType Management" privilege can store crafted input that, when later accessed by a user, executes arbitrary scripts in the user's browser [1][2].

Exploitation

Conditions To exploit this vulnerability, an attacker must have the "ContentType Management" privilege within Movable Type. They can then inject malicious code into the ContentData fields. When a privileged user (such as an administrator or other authorized user) views the Edit ContentData page, the injected script executes in their browser session [2]. The attack requires user interaction as the victim must access the malicious page.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the context of the Movable Type application. This can lead to session hijacking, defacement, or theft of sensitive data displayed on the page. The CVSS v3 base score is 4.8 (Medium), reflecting the need for high privileges and user interaction [1][2].

Mitigation

The vendor has released security updates to address this vulnerability. Affected versions include Movable Type 8.4.0 through 8.4.3, 8.0.0 through 8.0.7, and 7 r.5509 and earlier, as well as corresponding Premium versions. Users should upgrade to Movable Type 8.8.0, 8.4.4, 8.0.8, or 7 r.5510 (v7.906.5) or later [1][3]. For Movable Type Cloud, updates are available as per vendor guidance [2].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.