CVE-2026-23704
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
6.5 / 10
Vector String
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Vulnerability Description
A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-434
Source
NVD
Vendor
Six Apart Ltd.
Product
Movable Type (Software Edition), Movable Type Advanced (Software Edition), Movable Type Premium (Software Edition), Movable Type Premium (Advanced Edition) (Software Edition), Movable Type (Cloud Edition), Movable Type Premium (Cloud Edition)
Discussion (0)
Add Comment
No comments yet. Be the first!