Sixapart maintains Movable Type, a widely deployed content management and blogging platform that has held prominence in the landscape despite a narrow product scope. Vulnerabilities affecting this vendor concentrate in web-application input handling and code generation contexts, recurring through cross-site scripting, SQL injection, code injection, and cross-site request forgery weaknesses that are characteristic of server-side content engines. A meaningful share of disclosures reach serious severity, and the platform's public-facing nature and integration into publishing and community sites have contributed to a moderate tendency toward public exploit availability. Defenders should treat Movable Type instances, particularly internet-exposed installations, as requiring prompt patch cycles given the application's role in content authoring and user-generated content handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sixapart over time
Signals from CVEs in this vendor scope (66 CVEs).
66 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20837CRITICAL Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced | Oct 26, 2021 | 9.8 | 89 | NO | YES |
CVE-2015-1592HIGH Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attack | Feb 19, 2015 | 7.5 | 77 | NO | YES |
CVE-2013-0209HIGH lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote att | Jan 23, 2013 | 7.5 | 69 | NO | YES |
CVE-2026-33088CRITICAL Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement. | Apr 8, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-25776CRITICAL Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script. | Apr 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2016-5742CRITICAL SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows | Jan 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2020-5576HIGH Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earli | May 14, 2020 | 8.8 | 27 | NO | NO |
CVE-2010-4511HIGH Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic publishing error message." | Dec 9, 2010 | 10.0 | 27 | NO | NO |
CVE-2010-4509HIGH Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to the (1) mt:AssetProperty and (2) mt:Entry | Dec 9, 2010 | 10.0 | 27 | NO | NO |
CVE-2012-1503MEDIUM Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comm | Aug 29, 2014 | 4.3 | 26 | NO | YES |
Signals from CVEs in this vendor scope (66 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sixapart.
Media articles that mention a CVE ID that affects a product developed by Sixapart — matched by CVE ID, not by vendor name.