Movabletype
Vendor:
First CVE: Jun 16, 2003 · Active for 23 years
66
Total CVEs
More Total CVEs than 85% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Movabletype over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2003
23 years ago
Most Recent CVE
Apr 8, 2026
107 days ago
CVE Severity & Scoring
Movabletype66 CVEs
64%
21%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (37.9%)
Unknown41 (62.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (37.9%)
High0 (0.0%)
Unknown41 (62.1%)
User Interaction
None8 (12.1%)
Unknown41 (62.1%)
Required17 (25.8%)
Privileges Required
Low3 (4.5%)
High1 (1.5%)
None21 (31.8%)
Unknown41 (62.1%)
Top CVEs
Signals from CVEs in this product scope (66 CVEs).
66 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20837CRITICAL Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced | Oct 26, 2021 | 9.8 | 89 | NO | YES |
CVE-2015-1592HIGH Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attack | Feb 19, 2015 | 7.5 | 77 | NO | YES |
CVE-2013-0209HIGH lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote att | Jan 23, 2013 | 7.5 | 69 | NO | YES |
CVE-2026-33088CRITICAL Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement. | Apr 8, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-25776CRITICAL Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script. | Apr 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2016-5742CRITICAL SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows | Jan 23, 2017 | 9.8 | 30 | NO | NO |
CVE-2020-5576HIGH Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earli | May 14, 2020 | 8.8 | 27 | NO | NO |
CVE-2010-4511HIGH Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic publishing error message." | Dec 9, 2010 | 10.0 | 27 | NO | NO |
CVE-2010-4509HIGH Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to the (1) mt:AssetProperty and (2) mt:Entry | Dec 9, 2010 | 10.0 | 27 | NO | NO |
CVE-2012-1503MEDIUM Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comm | Aug 29, 2014 | 4.3 | 26 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (66 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
3.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.5% of CVEs· Bottom 1%
ExploitDB
4 CVEs
6.1% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (66 CVEs).
Media Mentions
Signals from CVEs in this product scope (66 CVEs).
Top CNAs Publishing CVEs For Movabletype
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| unknown | 1 | 4.3 | 1.1% | 0 | 0 |
| enterprise_1.02 | 1 | 4.3 | 1.3% | 0 | 0 |
| enterprise_1.01 | 1 | 4.3 | 1.3% | 0 | 0 |
| 9.1.0 | 2 | 9.8 | 0.4% | 0 | 0 |
| 9.0.6 | 2 | 9.8 | 0.4% | 0 | 0 |
| 9.0.5 | 2 | 9.8 | 0.4% | 0 | 0 |
| 6.5.1 | 1 | 6.1 | 0.9% | 0 | 0 |
| 6.5.0 | 1 | 6.1 | 0.9% | 0 | 0 |
| 6.2.4 | 1 | 9.8 | 1.6% | 0 | 0 |
| 6.2.2 | 1 | 9.8 | 1.6% | 0 | 0 |
| 6.2.0 | 1 | 9.8 | 1.6% | 0 | 0 |
| 6.1.2 | 1 | 9.8 | 1.6% | 0 | 0 |
| 6.1.1 | 1 | 9.8 | 1.6% | 0 | 0 |
| 6.1.0 | 1 | 9.8 | 1.6% | 0 | 0 |
| 6.0.8 | 1 | 9.8 | 1.6% | 0 | 0 |
| 6.0.7 | 2 | 8.7 | 2.7% | 0 | 0 |
| 6.0.6 | 2 | 8.7 | 2.7% | 0 | 0 |
| 6.0.5 | 3 | 8.5 | 2.4% | 0 | 0 |
| 6.0.4 | 3 | 8.5 | 2.4% | 0 | 0 |
| 6.0.3 | 3 | 8.5 | 2.4% | 0 | 0 |