Six Apart Movable Type
cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*, +2 more
- >= 8.4.0, <= 8.4.3
- >= 8.0.0, <= 8.0.7
- <= 7 r.5509
A stored cross-site scripting vulnerability has been identified in Movable Type, affecting versions 8.4.0 to 8.4.3, 8.0.0 to 8.0.7, and 7 r.5509 and earlier. This vulnerability allows an attacker with 'ContentType Management' privilege to inject crafted input that is stored and later executed as an arbitrary script in the web browser of users accessing the 'Edit ContentData' page. Similar vulnerability exists in the 'Edit CategorySet of ContentType' page, as detailed in CVE-2025-62499.
Exploitation of this vulnerability allows for the execution of injected scripts in the context of the user's browser, potentially leading to unauthorized actions or data exposure.
Users are advised to update to Movable Type versions 8.8.0, 8.4.4, 8.0.8, or 7 r.5510. For Movable Type Premium users, version 2.11 or 1.68 is recommended. Details on how to obtain these versions are available on the Six Apart website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.