CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Movabletype 4Movable Type Movable Type AdvancedMovable Type Premium+1 moreNov 21, 2024 Mar 5, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movab...Show more |
1Movabletype 4Movable Type Movable Type AdvancedMovable Type Premium+1 moreNov 21, 2024 Mar 5, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6...Show more |
1Movabletype 4Movable Type Movable Type AdvancedMovable Type Premium+1 moreNov 21, 2024 Mar 5, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Ty...Show more |
1Movabletype 4Movable Type Advanced Movable Type EnterpriseMovable Type Open Source+1 moreApr 29, 2026 Mar 3, 2012 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, which allows remote authenticated users to conduct directory traversal attacks and...Show more |
1Movabletype 4Movable Type Advanced Movable Type EnterpriseMovable Type Open Source+1 moreApr 29, 2026 Mar 3, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is incompletely installed, allows remote attackers to inject arbi...Show more |
1Movabletype 4Movable Type Advanced Movable Type EnterpriseMovable Type Open Source+1 moreApr 29, 2026 Mar 3, 2012 N/A· v4 N/A· v3 6.5 MEDIUM· v2 The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary commands by leveraging the file-upload feature, related to an "OS Comm...Show more |
1Movabletype 4Movable Type Advanced Movable Type EnterpriseMovable Type Open Source+1 moreApr 29, 2026 Mar 3, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a dif...Show more |