Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | Movabletype Movable TypeAI | 20/5/2026 | 24/7/2026 | Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed. | |
| Aplazada | Media (5.1) | 0.23% | — | Movabletype Movable TypeAI | 4/2/2026 | 17/6/2026 | A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well. | |
| Aplazada | Media (4.8) | 0.24% | — | Movabletype Movable TypeAI | 4/2/2026 | 17/6/2026 | Movable Type contains a stored cross-site scripting vulnerability in Export Sites. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well. | |
| Aplazada | Media (4.8) | 0.24% | — | Movabletype Movable TypeAI | 4/2/2026 | 17/6/2026 | Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well. | |
| Aplazada | Media (4.6) | 0.23% | — | Movabletype Movable TypeAI | 23/10/2025 | 17/6/2026 | Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit CategorySet of ContentType page. | |
| Aplazada | Media (4.6) | 0.23% | — | Movabletype Movable TypeAI | 23/10/2025 | 17/6/2026 | Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit ContentData page. | |
| Aplazada | Media (5.1) | 0.21% | — | Movabletype Movable TypeAI | 20/8/2025 | 17/6/2026 | URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the password reset page, which may lead to redirection to an arbitrary URL. | |
| Aplazada | Media (6.9) | 0.18% | — | Movabletype Movable TypeAI | 20/8/2025 | 17/6/2026 | Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote unauthenticated attacker. | |
| Aplazada | Media (6.1) | 0.26% | — | Movabletype Movable TypeAI | 19/2/2025 | 17/6/2026 | Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while logged in to the affected product, an arbitrary script may be executed on the web browser of the user. | |
| Aplazada | Media (5.4) | 0.22% | — | TinymceAIMovabletype Movable TypeAI | 19/2/2025 | 17/6/2026 | Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as a rich text editor and an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Media (5.4) | 0.22% | — | Movabletype Movable TypeAI | 19/2/2025 | 17/6/2026 | Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Modificada | Media (6.1) | 0.84% | — | Movabletype Movable TypeMovabletype Movable Type AdvancedMovabletype Movable Type PremiumMovabletype Movable Type Premium Advanced | 5/3/2021 | 17/6/2026 | Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote… | |
| Modificada | Media (6.1) | 0.84% | — | Movabletype Movable TypeMovabletype Movable Type AdvancedMovabletype Movable Type PremiumMovabletype Movable Type Premium Advanced | 5/3/2021 | 17/6/2026 | Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type Premium 1.39 and earlier, and Movable Type… | |
| Modificada | Media (6.1) | 0.84% | — | Movabletype Movable TypeMovabletype Movable Type AdvancedMovabletype Movable Type PremiumMovabletype Movable Type Premium Advanced | 5/3/2021 | 17/6/2026 | Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type Premium 1.39 and earlier, and Movable… | |
| Modificada | Alta (7.5) | 3.7% | — | Sixapart Movabletype | 17/4/2015 | 17/6/2026 | Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates. | |
| Modificada | Baja (3.5) | 0.97% | — | Sixapart Movabletype | 10/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management page in Six Apart Movable Type before 5.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.4% | — | Sixapart Movabletype | 10/1/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5.2.9, and 6.0.x before 6.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.8% | — | Movabletype Movable Type Open SourceMovabletype Movable Type EnterpriseMovabletype Movable Type AdvancedMovabletype Movable Type PRO | 3/3/2012 | 16/6/2026 | The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files by leveraging the template-designer role. | |
| Modificada | Media (4.3) | 1.9% | — | Movabletype Movable Type Open SourceMovabletype Movable Type EnterpriseMovabletype Movable Type AdvancedMovabletype Movable Type PRO | 3/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the dbuser parameter, a different vulnerability than CVE-2012-0318. | |
| Modificada | Media (6.5) | 2.4% | — | Movabletype Movable Type Open SourceMovabletype Movable Type EnterpriseMovabletype Movable Type AdvancedMovabletype Movable Type PRO | 3/3/2012 | 16/6/2026 | The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary commands by leveraging the file-upload feature, related to an "OS Command Injection" issue. | |
| Modificada | Media (4.3) | 1.3% | — | Movabletype Movable Type Open SourceMovabletype Movable Type EnterpriseMovabletype Movable Type AdvancedMovabletype Movable Type PRO | 3/3/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a different issue than CVE-2012-1262. | |
| Modificada | Alta (10) | 1.5% | — | Sixapart Movabletype | 9/12/2010 | 16/6/2026 | Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic publishing error message." | |
| Modificada | Alta (10) | 1.5% | — | Sixapart Movabletype | 9/12/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to the (1) mt:AssetProperty and (2) mt:EntryFlag tags. | |
| Modificada | Alta (7.5) | 1.3% | — | Sixapart Movabletype | 9/12/2010 | 16/6/2026 | SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Sixapart Movabletype | 9/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |