Skip to content
Noroxi

movabletype records

8 published records for vendor movabletype.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
50%
Median publish → KEV
No record has entered KEV

All records

8 records
  • CVE-2012-0319
    27Monitor

    The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute

    MediumCVSS 6.5No exploitEPSS 2%

    movabletype · movable type open sourceMar 3, 2012

  • Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable

    MediumCVSS 6.1No exploitEPSS 1%

    movabletype · movable typeMar 5, 2021

  • Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Mo

    MediumCVSS 6.1No exploitEPSS 1%

    movabletype · movable typeMar 5, 2021

  • Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Typ

    MediumCVSS 6.1No exploitEPSS 1%

    movabletype · movable typeMar 5, 2021

  • CVE-2012-1262
    18Monitor

    Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, wh

    MediumCVSS 4.3No exploitEPSS 2%

    movabletype · movable type open sourceMar 3, 2012

  • CVE-2012-1497
    17Monitor

    The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, whi

    MediumCVSS 4.0No exploitEPSS 2%

    movabletype · movable type open sourceMar 3, 2012

  • CVE-2012-0318
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attacke

    MediumCVSS 4.3No exploitEPSS 1%

    movabletype · movable type open sourceMar 3, 2012

  • CVE-2009-2480
    17Monitor

    Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized

    MediumCVSS 4.3No exploitEPSS 1%

    movabletype · six apart movable typeJul 16, 2009