VYPR

Movabletype

by Movabletype

Source repositories

CVEs (76)

  • CVE-2021-20808MedAug 26, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Search screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type…

  • CVE-2021-20665MedMar 5, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium…

  • CVE-2021-20664MedMar 5, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type…

  • CVE-2021-20663MedMar 5, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable…

  • CVE-2020-5575MedMay 14, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7),…

  • CVE-2020-5528MedFeb 6, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier (Movable Type 6.5), Movable Type Advanced 7 r.4603 and earlier (Movable Type Advanced 7), Movable Type Advanced 6.5.2 and earlier…

  • CVE-2019-6025MedDec 26, 2019
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Advanced 7 r.4602 (7.1.3) and…

  • CVE-2018-0672MedSep 4, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2026-22875MedFeb 4, 2026
    risk 0.35cvss 5.4epss 0.00

    Movable Type contains a stored cross-site scripting vulnerability in Export Sites. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are…

  • CVE-2026-21393MedFeb 4, 2026
    risk 0.35cvss 5.4epss 0.00

    Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are…

  • CVE-2025-24841MedFeb 19, 2025
    risk 0.35cvss 5.4epss 0.00

    Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as a rich text editor and an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2025-22888MedFeb 19, 2025
    risk 0.35cvss 5.4epss 0.00

    Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2023-45746MedOct 30, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/versions are as follows: Movable Type 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5405 and earlier…

  • CVE-2020-5669MedOct 26, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in Movable Type Movable Type Premium 1.37 and earlier and Movable Type Premium Advanced 1.37 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2020-5574MedMay 14, 2020
    risk 0.35cvss 5.3epss 0.01

    HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS…

  • CVE-2025-53522MedAug 20, 2025
    risk 0.34cvss 5.3epss 0.00

    Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote unauthenticated attacker.

  • CVE-2025-62499MedOct 23, 2025
    risk 0.31cvss 4.8epss 0.00

    Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit…

  • CVE-2025-54856MedOct 23, 2025
    risk 0.31cvss 4.8epss 0.00

    Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit ContentData page.

  • CVE-2026-44392MedMay 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.

  • CVE-2025-55706MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.00

    URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the password reset page, which may lead to redirection to an arbitrary URL.