Movable type (cloud edition)
This hub aggregates every CVE we track for Movable type (cloud edition), a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM8
Monthly trend
0
0
0
0
0
0
0
0
0
0
2
0
2
0
0
0
4
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 8 most recently published vulnerabilities affecting Movable type (cloud edition).
- CVE-2026-24447If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embe...6.5
- CVE-2026-23704A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable ...6.5
- CVE-2026-22875Movable Type contains a stored cross-site scripting vulnerability in Export Sites. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Not...5.4
- CVE-2026-21393Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Not...5.4
- CVE-2025-62499Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbi...4.8
- CVE-2025-54856Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script ma...4.8
- CVE-2025-55706URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the password reset page, which may l...4.3
- CVE-2025-53522Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote unauthenticated attacker.5.3
Product normalization is registry-driven with AI assist and human review. How it works