Movable Type Stored Cross-Site Scripting Vulnerability in MT Block Editor HTML Edit Mode

Vulnerability

A stored cross-site scripting vulnerability has been identified in Movable Type, specifically in versions through 8.4.1 of the 8.4.x and 8.0.x series, as well as in Movable Type Premium 2.06 and earlier. This vulnerability occurs in the HTML edit mode of the MT Block Editor when TinyMCE6 is used as a rich text editor. It allows for the execution of arbitrary scripts in the web browser of a logged-in user.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary scripts in the web browser of a logged-in user.

Remediation

Users are advised to update to Movable Type 8.4.2, 8.0.6, or Movable Type Premium 2.07. For detailed upgrade instructions, visit the Movable Type release notes.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.