Movable Type Stored Cross-Site Scripting Vulnerability in CategorySet Editing

Vulnerability

A stored cross-site scripting vulnerability has been identified in Movable Type, specifically within the Edit CategorySet of ContentType page. This issue affects users with 'ContentType Management' privileges, allowing an attacker to execute arbitrary scripts in the web browser of users who access the vulnerable page. The vulnerability is present in multiple versions of Movable Type, including the Software Edition, Cloud Edition, and Premium versions.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary scripts in the web browser of users accessing the Edit CategorySet of ContentType page.

Remediation

Users are advised to update to Movable Type versions 8.8.0, 8.4.4, 8.0.8, or 7 r.5510. For Movable Type Premium users, version 2.11 or 1.68 is recommended. Instructions for updating are available on the Six Apart user site or through the Movable Type documentation.

Added: Oct 23, 2025, 5:17 AM
Updated: Oct 23, 2025, 5:17 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
4.7
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.