Movable Type provided by Six Apart Ltd. contains multiple stored cross-site scripting vulnerabilities.
Movable Type Software Edition
- Movable Type / Movable Type Advanced
- 8.4.0 to 8.4.3 (8.4 series)
- 8.0.0 to 8.0.7 (8.0 series)
- 7 r.5509 and earlier (7 series)
- Movable Type Premium / Movable Type Premium (Advanced Edition)
- 2.10 and earlier (2 series)
- 1.67 and earlier (1 series)
- Movable Type
- 8.7.0 (8 series)
- 7 r.5509 (7 series)
- Movable Type Premium
- 2.10 (2 series)
- 1.67 (1 series)
Movable Type provided by Six Apart Ltd. contains multiple stored cross-site scripting vulnerabilities listed below.
- Stored cross-site scripting vulnerability in Edit ContentData page (CWE-79)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Base Score 4.6
- CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N Base Score 4.8
- CVE-2025-54856
- Stored cross-site scripting vulnerability in Edit CategorySet of ContentType page (CWE-79)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Base Score 4.6
- CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N Base Score 4.8
- CVE-2025-62499
If crafted input is stored by an attacker with "ContentType Management" privilege, the following impacts may occur.
- An arbitrary script may be executed on the web browser of the user who accesses Edit ContentData page (CVE-2025-54856)
- An arbitrary script may be executed on the web browser of the user who accesses Edit CategorySet of page (CVE-2025-62499)
Update the Software
Apply the appropriate update according to the information provided by the developer.
The developer has released the following updates that contain fixes for these vulnerabilities.
Movable Type Software Edition
- Movable Type / Movable Type Advanced
- 8.8.0 (8.8 series)
- 8.4.4 (8.4 series)
- 8.0.8 (8.0 series)
- 7 r.5510 (7 series)
- Movable Type Premium / Movable Type Premium(Advanced Edition)
- 2.11 (2 series)
- 1.68 (1 series)
- Movable Type
- 8.8.0 (8 series)
- 7 r.5510 (7 series)
- Movable Type Premium
- 2.11 (2 series)
- 1.68 (1 series)
| Vendor | Status | Last Update | Vendor Notes |
|---|---|---|---|
| Six Apart Ltd. | Vulnerable | 2025/10/22 | Six Apart Ltd. website |
Six Apart Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
JPCERT/CC and Six Apart Ltd. coordinated under the Information Security Early Warning Partnership.
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2025-54856 |
|
CVE-2025-62499 |
|
| JVN iPedia |
JVNDB-2025-000090 |