movabletype records
8 published records for vendor movabletype.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
27Monitor | CVE-2012-0319No exploit | The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute movabletype · movable type open source · CWE-94 | Medium6.5 | — | 2.4% | Mar 3, 2012 |
24Monitor | CVE-2021-20663No exploit | Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movablemovabletype · movable type · CWE-79 | Medium6.1 | — | 0.8% | Mar 5, 2021 |
24Monitor | CVE-2021-20665No exploit | Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Momovabletype · movable type · CWE-79 | Medium6.1 | — | 0.8% | Mar 5, 2021 |
24Monitor | CVE-2021-20664No exploit | Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Typmovabletype · movable type · CWE-79 | Medium6.1 | — | 0.8% | Mar 5, 2021 |
18Monitor | CVE-2012-1262No exploit | Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, whmovabletype · movable type open source · CWE-79 | Medium4.3 | — | 1.9% | Mar 3, 2012 |
17Monitor | CVE-2012-1497No exploit | The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, whimovabletype · movable type open source · CWE-22 | Medium4.0 | — | 1.8% | Mar 3, 2012 |
17Monitor | CVE-2012-0318No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackemovabletype · movable type open source · CWE-79 | Medium4.3 | — | 1.3% | Mar 3, 2012 |
17Monitor | CVE-2009-2480No exploit | Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initializedmovabletype · six apart movable type · CWE-79 | Medium4.3 | — | 1.3% | Jul 16, 2009 |
- CVE-2012-031927Monitor
The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute
MediumCVSS 6.5No exploitEPSS 2%movabletype · movable type open sourceMar 3, 2012
- CVE-2021-2066324Monitor
Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable
MediumCVSS 6.1No exploitEPSS 1%movabletype · movable typeMar 5, 2021
- CVE-2021-2066524Monitor
Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Mo
MediumCVSS 6.1No exploitEPSS 1%movabletype · movable typeMar 5, 2021
- CVE-2021-2066424Monitor
Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Typ
MediumCVSS 6.1No exploitEPSS 1%movabletype · movable typeMar 5, 2021
- CVE-2012-126218Monitor
Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, wh
MediumCVSS 4.3No exploitEPSS 2%movabletype · movable type open sourceMar 3, 2012
- CVE-2012-149717Monitor
The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, whi
MediumCVSS 4.0No exploitEPSS 2%movabletype · movable type open sourceMar 3, 2012
- CVE-2012-031817Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attacke
MediumCVSS 4.3No exploitEPSS 1%movabletype · movable type open sourceMar 3, 2012
- CVE-2009-248017Monitor
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized
MediumCVSS 4.3No exploitEPSS 1%movabletype · six apart movable typeJul 16, 2009