Sixapart

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 50
    Known Exploited: 0
    8
    Critical Level Threats
    11
    High Level Threats
    29
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-25776

    Code injection in Movable Type enables arbitrary Perl execution

    Last Modified: Apr 20, 2026
    Published: Apr 08, 2026

    CVE-2026-33088

    SQL Injection in Movable Type Enables Arbitrary Database Access

    Last Modified: Apr 20, 2026
    Published: Apr 08, 2026

    CVE-2023-45746

    Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/versions are as follows: Movable Type 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Premium 1.58 and earlier, Movable Type Premium Advanced 1.58 and earlier, Movable Type Cloud Edition (Version 7) r.5405 and earlier, and Movable Type Premium Cloud Edition 1.58 and earlier.

    Last Modified: Nov 21, 2024
    Published: Oct 30, 2023

    CVE-2022-45122

    Cross-site scripting vulnerability in Movable Type Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earlier (Movable Type Advanced 7 Series), Movable Type 6.8.7 and earlier (Movable Type 6 Series), Movable Type Advanced 6.8.7 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.53 and earlier, and Movable Type Premium Advanced 1.53 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

    Last Modified: Apr 23, 2025
    Published: Dec 07, 2022

    CVE-2022-43660

    Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege of 'Manage of Content Types' may execute an arbitrary Perl script and/or an arbitrary OS command. Affected products/versions are as follows: Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.53 and earlier, and Movable Type Premium Advanced 1.53 and earlier.

    Last Modified: Apr 23, 2025
    Published: Dec 07, 2022
    Items Per Page