Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/sixapart/movabletype

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.

Join the discussion

A critical code injection vulnerability (CVE-2026-25776) exists in Six Apart Ltd. 's Movable Type version 9.1.0 and earlier. This flaw allows an unauthenticated attacker to execute arbitrary Perl scripts on the affected system. The vulnerability has a high CVSS score of 9.8, indicating severe impact on confidentiality, integrity, and availability. No official patch or remediation guidance is currently documented. There are no known exploits in the wild at this time. Users of affected versions should monitor vendor advisories for updates and apply patches once available.

Join the discussion

CVE-2026-33088 is an SQL Injection vulnerability in Six Apart Ltd. 's Movable Type product versions 9.1.0 and earlier. This flaw allows an attacker to execute arbitrary SQL statements due to improper neutralization of special elements in SQL commands. The vulnerability has a CVSS 3.0 score of 7.3, indicating high severity with potential impacts on confidentiality, integrity, and availability. No official patch or remediation guidance is currently provided by the vendor. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-24447 is a medium severity vulnerability in Six Apart Ltd. 's Movable Type (Software Edition) affecting versions 8.0.2 to 9.0.5. It involves improper neutralization of formula elements in CSV files generated by the product, allowing maliciously crafted data to embed executable code within CSV exports. When a user downloads and opens such a CSV file in spreadsheet software, the embedded code may execute, potentially compromising the user's environment. The vulnerability requires at least limited privileges to generate the malformed CSV and user interaction to open the file. End-of-life versions 7 and 8.

Join the discussion

CVE-2026-23704 is a medium-severity vulnerability in Six Apart Ltd. 's Movable Type (Software Edition) versions 8.0.2 to 8.0.8, 8.8.0 to 8.8.1, and 9.

Join the discussion

CVE-2026-22875 is a stored cross-site scripting (XSS) vulnerability affecting Six Apart Ltd. 's Movable Type (Software Edition) versions 8.0.2 to 8.0.8, 8.8.0 to 8.8.1, and 9.

Join the discussion

CVE-2026-21393 is a stored cross-site scripting (XSS) vulnerability affecting Six Apart Ltd. 's Movable Type (Software Edition) versions 8.0.2 to 8.0.8, 8.8.0 to 8.8.1, and 9.

Join the discussion

Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit CategorySet of ContentType page.

Join the discussion

Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit ContentData page.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/sixapart/movabletype
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses