Skip to content
Noroxi

sixapart records

50 published records for vendor sixapart.

All records

50 records
  • CVE-2021-20837
    65This week

    Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r

    CriticalCVSS 9.8Proof of conceptEPSS 88%

    sixapart · movable typeOct 26, 2021

  • Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::t

    HighCVSS 7.5WeaponizedEPSS 75%

    debian · debian linuxFeb 19, 2015

  • lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migr

    HighCVSS 7.5WeaponizedEPSS 45%

    sixapart · movable typeJan 22, 2013

  • Movable Type XMLRPC API provided by Six Apart Ltd.

    CriticalCVSS 9.8No exploitEPSS 2%

    sixapart · movable typeAug 24, 2022

  • Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic

    CriticalCVSS 10.0No exploitEPSS 2%

    sixapart · movabletypeDec 9, 2010

  • Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to t

    CriticalCVSS 10.0No exploitEPSS 1%

    sixapart · movabletypeDec 9, 2010

  • Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly related

    CriticalCVSS 10.0No exploitEPSS 1%

    sixapart · movable typeMar 2, 2009

  • CVE-2016-5742
    39Monitor

    SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Ty

    CriticalCVSS 9.8No exploitEPSS 2%

    sixapart · movable typeJan 23, 2017

  • Movable Type provided by Six Apart Ltd.

    CriticalCVSS 9.3No exploitEPSS 1%

    sixapart · movable typeApr 8, 2026

  • CVE-2020-5577
    36Monitor

    Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable

    HighCVSS 8.8No exploitEPSS 2%

    sixapart · movable typeMay 13, 2020

  • CVE-2020-5576
    35Monitor

    Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable

    HighCVSS 8.8No exploitEPSS 1%

    sixapart · movable typeMay 13, 2020

  • CVE-2015-0845
    31Monitor

    Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remo

    HighCVSS 7.5No exploitEPSS 4%

    sixapart · movabletypeApr 17, 2015

  • CVE-2013-2184
    31Monitor

    Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the

    HighCVSS 7.5No exploitEPSS 4%

    sixapart · movable typeMar 27, 2015

  • CVE-2012-0320
    31Monitor

    Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectors

    HighCVSS 7.5No exploitEPSS 3%

    sixapart · movable typeMar 3, 2012

  • CVE-2011-5085
    31Monitor

    Unspecified vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to read or modify data via unknown vec

    HighCVSS 7.5No exploitEPSS 2%

    sixapart · movable typeApr 2, 2012

  • CVE-2014-9057
    31Monitor

    SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote at

    HighCVSS 7.5No exploitEPSS 2%

    debian · debian linuxDec 16, 2014

  • CVE-2010-3922
    30Monitor

    SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands vi

    HighCVSS 7.5No exploitEPSS 1%

    sixapart · movabletypeDec 9, 2010

  • Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with P

    HighCVSS 7.2No exploitEPSS 1%

    sixapart · movable typeDec 7, 2022

  • CVE-2012-0317
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote

    MediumCVSS 6.8No exploitEPSS 1%

    sixapart · movable typeMar 3, 2012

  • Movable Type provided by Six Apart Ltd.

    MediumCVSS 6.9No exploitEPSS 0%

    sixapart · movable typeApr 8, 2026

  • Improper validation of syntactic correctness of input vulnerability exist in Movable Type series.

    MediumCVSS 6.5No exploitEPSS 1%

    sixapart · movable typeDec 7, 2022

  • CVE-2020-5575
    24Monitor

    Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced

    MediumCVSS 6.1No exploitEPSS 1%

    sixapart · movable typeMay 13, 2020

  • Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series),

    MediumCVSS 6.1No exploitEPSS 1%

    sixapart · movable typeAug 25, 2021

  • Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and ear

    MediumCVSS 6.1No exploitEPSS 1%

    sixapart · movable typeAug 25, 2021

  • Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Typ

    MediumCVSS 6.1No exploitEPSS 1%

    sixapart · movable typeAug 25, 2021