Sixapart

Movable Type

39 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Published 30.10.2023 05:15:09
  • Last modified 21.11.2024 08:27:17

Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/versions are as follows: Movable Type 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Advance...

  • EPSS 0.65%
  • Published 07.12.2022 04:15:11
  • Last modified 23.04.2025 19:16:24

Cross-site scripting vulnerability in Movable Type Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earlier (Movable Type Advanced 7 Series), Movable Type 6.8.7 and earlier (Movable Type 6 Series), Movable...

  • EPSS 0.12%
  • Published 07.12.2022 04:15:11
  • Last modified 23.04.2025 16:15:27

Improper validation of syntactic correctness of input vulnerability exist in Movable Type series. Having a user to access a specially crafted URL may allow a remote unauthenticated attacker to set a specially crafted URL to the Reset Password page an...

  • EPSS 0.5%
  • Published 07.12.2022 04:15:10
  • Last modified 23.04.2025 14:15:22

Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege of 'Manage of Content Types' may execute an arbitrary Perl script and/or an arbitrary OS command. Aff...

  • EPSS 5.23%
  • Published 24.08.2022 09:15:08
  • Last modified 21.11.2024 07:15:44

Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be...

  • EPSS 0.21%
  • Published 26.10.2021 11:15:07
  • Last modified 21.11.2024 05:34:27

Cross-site scripting vulnerability in Movable Type Movable Type Premium 1.37 and earlier and Movable Type Premium Advanced 1.37 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

Exploit
  • EPSS 93.76%
  • Published 26.10.2021 06:15:06
  • Last modified 21.11.2024 05:47:15

Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Adva...

  • EPSS 0.35%
  • Published 26.08.2021 02:15:11
  • Last modified 21.11.2024 05:47:13

Cross-site scripting vulnerability in Edit screen of Content Data of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series) and Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series)) allows remote attackers to i...

  • EPSS 0.35%
  • Published 26.08.2021 02:15:11
  • Last modified 21.11.2024 05:47:13

Cross-site scripting vulnerability in Search screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced ...

  • EPSS 0.35%
  • Published 26.08.2021 02:15:11
  • Last modified 21.11.2024 05:47:13

Cross-site scripting vulnerability in Create screens of Entry, Page, and Content Type of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 a...