Six Apart's vulnerability footprint centers on Movable Type, a web publishing and content-management platform that has served as a foundation for blogs and small-to-medium-sized publishing workflows. The durable signal in its disclosures reflects the platform's role as a server-side application handling user input and authentication: recurring weaknesses cluster around cross-site scripting, improper authentication mechanisms, and input-handling gaps characteristic of content-management systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Six Apart over time
Signals from CVEs in this vendor scope (66 CVEs).
66 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20837CRITICAL Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced | Oct 26, 2021 | 9.8 | 89 | NO | YES |
CVE-2015-1592HIGH Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attack | Feb 19, 2015 | 7.5 | 77 | NO | YES |
CVE-2013-0209HIGH lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote att | Jan 23, 2013 | 7.5 | 69 | NO | YES |
CVE-2026-33088CRITICAL Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement. | Apr 8, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-25776CRITICAL Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script. | Apr 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2016-5742CRITICAL SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows | Jan 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2020-5576HIGH Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earli | May 14, 2020 | 8.8 | 27 | NO | NO |
CVE-2010-4511HIGH Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic publishing error message." | Dec 9, 2010 | 10.0 | 27 | NO | NO |
CVE-2010-4509HIGH Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to the (1) mt:AssetProperty and (2) mt:Entry | Dec 9, 2010 | 10.0 | 27 | NO | NO |
CVE-2012-1503MEDIUM Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comm | Aug 29, 2014 | 4.3 | 26 | NO | YES |
Signals from CVEs in this vendor scope (66 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Six Apart.
Media articles that mention a CVE ID that affects a product developed by Six Apart — matched by CVE ID, not by vendor name.