sixapart kayıtları
sixapart üreticisine ait 50 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %4
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %22
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-287 Improper Authentication2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
50 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
65Bu hafta | CVE-2021-20837Kavram kanıtı | Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 rsixapart · movable type · CWE-78 | Kritik9,8 | — | %88,1 | 26 Eki 2021 |
53Planlayın | CVE-2015-1592Silahlaştırılmış | Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::tdebian · debian linux · CWE-74 | Yüksek7,5 | — | %75,4 | 19 Şub 2015 |
44Planlayın | CVE-2013-0209Silahlaştırılmış | lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migrsixapart · movable type · CWE-287 | Yüksek7,5 | — | %45,2 | 22 Oca 2013 |
40Planlayın | CVE-2022-38078İstismar yok | Movable Type XMLRPC API provided by Six Apart Ltd.sixapart · movable type · CWE-94 | Kritik9,8 | — | %2,1 | 24 Ağu 2022 |
40Planlayın | CVE-2010-4511İstismar yok | Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic sixapart · movabletype | Kritik10,0 | — | %1,5 | 9 Ara 2010 |
40Planlayın | CVE-2010-4509İstismar yok | Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to tsixapart · movabletype | Kritik10,0 | — | %1,5 | 9 Ara 2010 |
40Planlayın | CVE-2009-0752İstismar yok | Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly relatedsixapart · movable type | Kritik10,0 | — | %1,4 | 2 Mar 2009 |
39İzleyin | CVE-2016-5742İstismar yok | SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Tysixapart · movable type · CWE-89 | Kritik9,8 | — | %1,6 | 23 Oca 2017 |
37İzleyin | CVE-2026-25776İstismar yok | Movable Type provided by Six Apart Ltd.sixapart · movable type · CWE-94 | Kritik9,3 | — | %0,7 | 8 Nis 2026 |
36İzleyin | CVE-2020-5577İstismar yok | Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movablesixapart · movable type · CWE-434 | Yüksek8,8 | — | %1,7 | 13 May 2020 |
35İzleyin | CVE-2020-5576İstismar yok | Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable sixapart · movable type · CWE-352 | Yüksek8,8 | — | %0,8 | 13 May 2020 |
31İzleyin | CVE-2015-0845İstismar yok | Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remosixapart · movabletype · CWE-94 | Yüksek7,5 | — | %3,7 | 17 Nis 2015 |
31İzleyin | CVE-2013-2184İstismar yok | Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via thesixapart · movable type · CWE-17 | Yüksek7,5 | — | %3,6 | 27 Mar 2015 |
31İzleyin | CVE-2012-0320İstismar yok | Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectorssixapart · movable type | Yüksek7,5 | — | %2,7 | 3 Mar 2012 |
31İzleyin | CVE-2011-5085İstismar yok | Unspecified vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to read or modify data via unknown vecsixapart · movable type | Yüksek7,5 | — | %2,0 | 2 Nis 2012 |
31İzleyin | CVE-2014-9057İstismar yok | SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote atdebian · debian linux · CWE-89 | Yüksek7,5 | — | %2,0 | 16 Ara 2014 |
30İzleyin | CVE-2010-3922İstismar yok | SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands visixapart · movabletype · CWE-89 | Yüksek7,5 | — | %1,3 | 9 Ara 2010 |
28İzleyin | CVE-2022-43660İstismar yok | Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Psixapart · movable type · CWE-94 | Yüksek7,2 | — | %1,0 | 7 Ara 2022 |
27İzleyin | CVE-2012-0317İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote sixapart · movable type · CWE-352 | Orta6,8 | — | %1,1 | 3 Mar 2012 |
27İzleyin | CVE-2026-33088İstismar yok | Movable Type provided by Six Apart Ltd.sixapart · movable type · CWE-89 | Orta6,9 | — | %0,5 | 8 Nis 2026 |
26İzleyin | CVE-2022-45113İstismar yok | Improper validation of syntactic correctness of input vulnerability exist in Movable Type series.sixapart · movable type · CWE-20 | Orta6,5 | — | %0,6 | 7 Ara 2022 |
24İzleyin | CVE-2020-5575İstismar yok | Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advancedsixapart · movable type · CWE-79 | Orta6,1 | — | %1,0 | 13 May 2020 |
24İzleyin | CVE-2021-20810İstismar yok | Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), sixapart · movable type · CWE-79 | Orta6,1 | — | %0,9 | 25 Ağu 2021 |
24İzleyin | CVE-2021-20814İstismar yok | Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and earsixapart · movable type · CWE-79 | Orta6,1 | — | %0,9 | 25 Ağu 2021 |
24İzleyin | CVE-2021-20812İstismar yok | Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Typsixapart · movable type · CWE-79 | Orta6,1 | — | %0,9 | 25 Ağu 2021 |
- CVE-2021-2083765Bu hafta
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r
KritikCVSS 9,8Kavram kanıtıEPSS %88sixapart · movable type26 Eki 2021
- CVE-2015-159253Planlayın
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::t
YüksekCVSS 7,5SilahlaştırılmışEPSS %75debian · debian linux19 Şub 2015
- CVE-2013-020944Planlayın
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migr
YüksekCVSS 7,5SilahlaştırılmışEPSS %45sixapart · movable type22 Oca 2013
- CVE-2022-3807840Planlayın
Movable Type XMLRPC API provided by Six Apart Ltd.
KritikCVSS 9,8İstismar yokEPSS %2sixapart · movable type24 Ağu 2022
- CVE-2010-451140Planlayın
Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic
KritikCVSS 10,0İstismar yokEPSS %2sixapart · movabletype9 Ara 2010
- CVE-2010-450940Planlayın
Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to t
KritikCVSS 10,0İstismar yokEPSS %2sixapart · movabletype9 Ara 2010
- CVE-2009-075240Planlayın
Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly related
KritikCVSS 10,0İstismar yokEPSS %1sixapart · movable type2 Mar 2009
- CVE-2016-574239İzleyin
SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Ty
KritikCVSS 9,8İstismar yokEPSS %2sixapart · movable type23 Oca 2017
- CVE-2026-2577637İzleyin
Movable Type provided by Six Apart Ltd.
KritikCVSS 9,3İstismar yokEPSS %1sixapart · movable type8 Nis 2026
- CVE-2020-557736İzleyin
Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable
YüksekCVSS 8,8İstismar yokEPSS %2sixapart · movable type13 May 2020
- CVE-2020-557635İzleyin
Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable
YüksekCVSS 8,8İstismar yokEPSS %1sixapart · movable type13 May 2020
- CVE-2015-084531İzleyin
Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remo
YüksekCVSS 7,5İstismar yokEPSS %4sixapart · movabletype17 Nis 2015
- CVE-2013-218431İzleyin
Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the
YüksekCVSS 7,5İstismar yokEPSS %4sixapart · movable type27 Mar 2015
- CVE-2012-032031İzleyin
Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectors
YüksekCVSS 7,5İstismar yokEPSS %3sixapart · movable type3 Mar 2012
- CVE-2011-508531İzleyin
Unspecified vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to read or modify data via unknown vec
YüksekCVSS 7,5İstismar yokEPSS %2sixapart · movable type2 Nis 2012
- CVE-2014-905731İzleyin
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote at
YüksekCVSS 7,5İstismar yokEPSS %2debian · debian linux16 Ara 2014
- CVE-2010-392230İzleyin
SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands vi
YüksekCVSS 7,5İstismar yokEPSS %1sixapart · movabletype9 Ara 2010
- CVE-2022-4366028İzleyin
Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with P
YüksekCVSS 7,2İstismar yokEPSS %1sixapart · movable type7 Ara 2022
- CVE-2012-031727İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote
OrtaCVSS 6,8İstismar yokEPSS %1sixapart · movable type3 Mar 2012
- CVE-2026-3308827İzleyin
Movable Type provided by Six Apart Ltd.
OrtaCVSS 6,9İstismar yokEPSS %0sixapart · movable type8 Nis 2026
- CVE-2022-4511326İzleyin
Improper validation of syntactic correctness of input vulnerability exist in Movable Type series.
OrtaCVSS 6,5İstismar yokEPSS %1sixapart · movable type7 Ara 2022
- CVE-2020-557524İzleyin
Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced
OrtaCVSS 6,1İstismar yokEPSS %1sixapart · movable type13 May 2020
- CVE-2021-2081024İzleyin
Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series),
OrtaCVSS 6,1İstismar yokEPSS %1sixapart · movable type25 Ağu 2021
- CVE-2021-2081424İzleyin
Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and ear
OrtaCVSS 6,1İstismar yokEPSS %1sixapart · movable type25 Ağu 2021
- CVE-2021-2081224İzleyin
Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Typ
OrtaCVSS 6,1İstismar yokEPSS %1sixapart · movable type25 Ağu 2021