Movable Type Stored Cross-Site Scripting Vulnerability in Content Editing Pages

Vulnerability

A stored cross-site scripting vulnerability has been identified in Movable Type, affecting versions 8.4.0 to 8.4.3, 8.0.0 to 8.0.7, and 7 r.5509 and earlier. This vulnerability allows an attacker with 'ContentType Management' privilege to inject crafted input that is stored and later executed as an arbitrary script in the web browser of users accessing the 'Edit ContentData' page. Similar vulnerability exists in the 'Edit CategorySet of ContentType' page, as detailed in CVE-2025-62499.

Impact

Exploitation of this vulnerability allows for the execution of injected scripts in the context of the user's browser, potentially leading to unauthorized actions or data exposure.

Remediation

Users are advised to update to Movable Type versions 8.8.0, 8.4.4, 8.0.8, or 7 r.5510. For Movable Type Premium users, version 2.11 or 1.68 is recommended. Details on how to obtain these versions are available on the Six Apart website.

Added: Oct 23, 2025, 5:22 AM
Updated: Oct 23, 2025, 5:22 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
4.7
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.