Movable Type Stored Cross-Site Scripting Vulnerability in MT Block Editor

Vulnerability

A stored cross-site scripting vulnerability has been identified in Movable Type and Movable Type Advanced, affecting versions through 8.4.1 and 8.0.5, as well as various 2.x and cloud editions. The vulnerability resides in the custom block edit page of the MT Block Editor, where an attacker can execute arbitrary scripts in the web browser of a logged-in user.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary scripts in the web browser of a logged-in user.

Remediation

Users are advised to update to Movable Type 8.4.2, 8.0.6, or version 7 r.5507 (v7.906.2). Movable Type Premium users should upgrade to version 2.07. For Movable Type Cloud Edition users, version 8.5.0 is available. Consult the Movable Type release notes for detailed upgrade instructions.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.