VYPR

Movabletype

by Movabletype

Source repositories

CVEs (2)

  • CVE-2025-25054MedFeb 19, 2025
    risk 0.40cvss 6.1epss 0.00

    Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while logged in to the affected product, an arbitrary script may be executed on the web browser of the user.

  • CVE-2026-44392MedMay 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.