Movable Type, a content management system provided by Six Apart Ltd., contains a critical SQL injection vulnerability (CVE-2026-33088) that permits unauthenticated attackers to execute arbitrary SQL statements against affected installations. The vulnerability presents a CVSS 3.1 score of 9.8 (CRITICAL), reflecting its network-accessible nature, low attack complexity, and lack of required authentication or user interaction. Exploitation could result in complete compromise of system confidentiality, integrity, and availability, enabling attackers to extract sensitive data, modify or delete database contents, and potentially escalate privileges. Although the exploit probability (EPSS) is currently low at 0.000360000, the vulnerability is listed on CISA's Known Exploited Vulnerabilities Catalog as ACTIVE and included on the Hot List, indicating active exploitation attempts in the wild. Organizations running affected versions of Movable Type should prioritize immediate patching and implement network segmentation controls to limit exposure while updates are deployed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.2, < 8.0.10CPE matchmatch criteria | cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:* | ||
>= 8.8.0, < 8.8.3CPE matchmatch criteria | cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:* | ||
>= 9.0.1, < 9.0.7CPE matchmatch criteria | cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:* | ||
9.1.0CPE matchmatch criteria | cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:advanced:*:*:* | ||
<= 2.14CPE matchmatch criteria | cpe:2.3:a:sixapart:movable_type:*:*:*:*:premium_advanced:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.