CVE-2026-25776

Severity CVSS v4.0:
CRITICAL
Type:
CWE-94 Code Injection
Publication date:
08/04/2026
Last modified:
20/04/2026

Description

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sixapart:movable_type:*:*:*:*:premium_advanced:*:*:* 2.14 (including)
cpe:2.3:a:sixapart:movable_type:9.0.5:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.0.6:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:* 8.0.2 (including) 8.0.10 (excluding)
cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:* 8.8.0 (including) 8.8.3 (excluding)
cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:* 9.0.1 (including) 9.0.7 (excluding)
cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:advanced:*:*:*