Movable type premium cloud edition
This hub aggregates every CVE we track for Movable type premium cloud edition, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
9
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM9
Monthly trend
0
0
0
0
0
0
0
0
0
0
2
0
2
0
0
0
4
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 9 most recently published vulnerabilities affecting Movable type premium cloud edition.
- CVE-2026-24447If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embe...6.5
- CVE-2026-23704A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable ...6.5
- CVE-2026-22875Movable Type contains a stored cross-site scripting vulnerability in Export Sites. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Not...5.4
- CVE-2026-21393Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Not...5.4
- CVE-2025-62499Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbi...4.8
- CVE-2025-54856Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script ma...4.8
- CVE-2025-55706URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the password reset page, which may l...4.3
- CVE-2025-53522Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote unauthenticated attacker.5.3
- CVE-2023-45746Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/versions are as follows: Movable Type 7 r.5405 and ...5.4
Product normalization is registry-driven with AI assist and human review. How it works