sixapart records
50 published records for vendor sixapart.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 4%
- Pre-auth RCE
- 9
- With a fix record
- 22%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-287 Improper Authentication2
The weakness classes this vendor ships most often: where to look.
CWEAll records
50 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
65This week | CVE-2021-20837Proof of concept | Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 rsixapart · movable type · CWE-78 | Critical9.8 | — | 88.1% | Oct 26, 2021 |
52Plan | CVE-2015-1592Weaponized | Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::tdebian · debian linux · CWE-74 | High7.5 | — | 74.8% | Feb 19, 2015 |
44Plan | CVE-2013-0209Weaponized | lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migrsixapart · movable type · CWE-287 | High7.5 | — | 45.2% | Jan 22, 2013 |
40Plan | CVE-2022-38078No exploit | Movable Type XMLRPC API provided by Six Apart Ltd.sixapart · movable type · CWE-94 | Critical9.8 | — | 2.1% | Aug 24, 2022 |
40Plan | CVE-2010-4511No exploit | Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic sixapart · movabletype | Critical10.0 | — | 1.5% | Dec 9, 2010 |
40Plan | CVE-2010-4509No exploit | Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to tsixapart · movabletype | Critical10.0 | — | 1.5% | Dec 9, 2010 |
40Plan | CVE-2009-0752No exploit | Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly relatedsixapart · movable type | Critical10.0 | — | 1.4% | Mar 2, 2009 |
39Monitor | CVE-2016-5742No exploit | SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Tysixapart · movable type · CWE-89 | Critical9.8 | — | 1.6% | Jan 23, 2017 |
37Monitor | CVE-2026-25776No exploit | Movable Type provided by Six Apart Ltd.sixapart · movable type · CWE-94 | Critical9.3 | — | 1.0% | Apr 8, 2026 |
36Monitor | CVE-2020-5577No exploit | Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movablesixapart · movable type · CWE-434 | High8.8 | — | 1.7% | May 13, 2020 |
35Monitor | CVE-2020-5576No exploit | Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable sixapart · movable type · CWE-352 | High8.8 | — | 0.8% | May 13, 2020 |
31Monitor | CVE-2015-0845No exploit | Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remosixapart · movabletype · CWE-94 | High7.5 | — | 3.7% | Apr 17, 2015 |
31Monitor | CVE-2013-2184No exploit | Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via thesixapart · movable type · CWE-17 | High7.5 | — | 3.6% | Mar 27, 2015 |
31Monitor | CVE-2012-0320No exploit | Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectorssixapart · movable type | High7.5 | — | 2.7% | Mar 3, 2012 |
31Monitor | CVE-2011-5085No exploit | Unspecified vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to read or modify data via unknown vecsixapart · movable type | High7.5 | — | 2.0% | Apr 2, 2012 |
31Monitor | CVE-2014-9057No exploit | SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote atdebian · debian linux · CWE-89 | High7.5 | — | 2.0% | Dec 16, 2014 |
30Monitor | CVE-2010-3922No exploit | SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands visixapart · movabletype · CWE-89 | High7.5 | — | 1.3% | Dec 9, 2010 |
28Monitor | CVE-2022-43660No exploit | Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Psixapart · movable type · CWE-94 | High7.2 | — | 1.0% | Dec 7, 2022 |
27Monitor | CVE-2012-0317No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote sixapart · movable type · CWE-352 | Medium6.8 | — | 1.1% | Mar 3, 2012 |
27Monitor | CVE-2026-33088No exploit | Movable Type provided by Six Apart Ltd.sixapart · movable type · CWE-89 | Medium6.9 | — | 0.5% | Apr 8, 2026 |
26Monitor | CVE-2022-45113No exploit | Improper validation of syntactic correctness of input vulnerability exist in Movable Type series.sixapart · movable type · CWE-20 | Medium6.5 | — | 0.6% | Dec 7, 2022 |
24Monitor | CVE-2020-5575No exploit | Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advancedsixapart · movable type · CWE-79 | Medium6.1 | — | 1.0% | May 13, 2020 |
24Monitor | CVE-2021-20810No exploit | Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), sixapart · movable type · CWE-79 | Medium6.1 | — | 0.9% | Aug 25, 2021 |
24Monitor | CVE-2021-20814No exploit | Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and earsixapart · movable type · CWE-79 | Medium6.1 | — | 0.9% | Aug 25, 2021 |
24Monitor | CVE-2021-20812No exploit | Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Typsixapart · movable type · CWE-79 | Medium6.1 | — | 0.9% | Aug 25, 2021 |
- CVE-2021-2083765This week
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r
CriticalCVSS 9.8Proof of conceptEPSS 88%sixapart · movable typeOct 26, 2021
- CVE-2015-159252Plan
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::t
HighCVSS 7.5WeaponizedEPSS 75%debian · debian linuxFeb 19, 2015
- CVE-2013-020944Plan
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migr
HighCVSS 7.5WeaponizedEPSS 45%sixapart · movable typeJan 22, 2013
- CVE-2022-3807840Plan
Movable Type XMLRPC API provided by Six Apart Ltd.
CriticalCVSS 9.8No exploitEPSS 2%sixapart · movable typeAug 24, 2022
- CVE-2010-451140Plan
Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic
CriticalCVSS 10.0No exploitEPSS 2%sixapart · movabletypeDec 9, 2010
- CVE-2010-450940Plan
Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to t
CriticalCVSS 10.0No exploitEPSS 1%sixapart · movabletypeDec 9, 2010
- CVE-2009-075240Plan
Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly related
CriticalCVSS 10.0No exploitEPSS 1%sixapart · movable typeMar 2, 2009
- CVE-2016-574239Monitor
SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Ty
CriticalCVSS 9.8No exploitEPSS 2%sixapart · movable typeJan 23, 2017
- CVE-2026-2577637Monitor
Movable Type provided by Six Apart Ltd.
CriticalCVSS 9.3No exploitEPSS 1%sixapart · movable typeApr 8, 2026
- CVE-2020-557736Monitor
Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable
HighCVSS 8.8No exploitEPSS 2%sixapart · movable typeMay 13, 2020
- CVE-2020-557635Monitor
Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable
HighCVSS 8.8No exploitEPSS 1%sixapart · movable typeMay 13, 2020
- CVE-2015-084531Monitor
Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remo
HighCVSS 7.5No exploitEPSS 4%sixapart · movabletypeApr 17, 2015
- CVE-2013-218431Monitor
Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the
HighCVSS 7.5No exploitEPSS 4%sixapart · movable typeMar 27, 2015
- CVE-2012-032031Monitor
Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectors
HighCVSS 7.5No exploitEPSS 3%sixapart · movable typeMar 3, 2012
- CVE-2011-508531Monitor
Unspecified vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to read or modify data via unknown vec
HighCVSS 7.5No exploitEPSS 2%sixapart · movable typeApr 2, 2012
- CVE-2014-905731Monitor
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote at
HighCVSS 7.5No exploitEPSS 2%debian · debian linuxDec 16, 2014
- CVE-2010-392230Monitor
SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5No exploitEPSS 1%sixapart · movabletypeDec 9, 2010
- CVE-2022-4366028Monitor
Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with P
HighCVSS 7.2No exploitEPSS 1%sixapart · movable typeDec 7, 2022
- CVE-2012-031727Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote
MediumCVSS 6.8No exploitEPSS 1%sixapart · movable typeMar 3, 2012
- CVE-2026-3308827Monitor
Movable Type provided by Six Apart Ltd.
MediumCVSS 6.9No exploitEPSS 0%sixapart · movable typeApr 8, 2026
- CVE-2022-4511326Monitor
Improper validation of syntactic correctness of input vulnerability exist in Movable Type series.
MediumCVSS 6.5No exploitEPSS 1%sixapart · movable typeDec 7, 2022
- CVE-2020-557524Monitor
Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced
MediumCVSS 6.1No exploitEPSS 1%sixapart · movable typeMay 13, 2020
- CVE-2021-2081024Monitor
Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series),
MediumCVSS 6.1No exploitEPSS 1%sixapart · movable typeAug 25, 2021
- CVE-2021-2081424Monitor
Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and ear
MediumCVSS 6.1No exploitEPSS 1%sixapart · movable typeAug 25, 2021
- CVE-2021-2081224Monitor
Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Typ
MediumCVSS 6.1No exploitEPSS 1%sixapart · movable typeAug 25, 2021