Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2025-25054

Disclosure Date: February 19, 2025 (last updated February 19, 2025)
Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while logged in to the affected product, an arbitrary script may be executed on the web browser of the user.
0
Attacker Value
Unknown

CVE-2025-24841

Disclosure Date: February 19, 2025 (last updated February 19, 2025)
Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as a rich text editor and an arbitrary script may be executed on a logged-in user's web browser.
0
Attacker Value
Unknown

CVE-2025-22888

Disclosure Date: February 19, 2025 (last updated February 19, 2025)
Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be executed on a logged-in user's web browser.
0
Attacker Value
Unknown

CVE-2009-2492

Disclosure Date: July 17, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.
0
Attacker Value
Unknown

CVE-2007-0604

Disclosure Date: January 30, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Movable Type (MT) before 3.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the MTCommentPreviewIsStatic tag, which can open the "comment entry screen," a different vulnerability than CVE-2007-0231.
0