Movable Type contains a stored cross-site scripting vulnerability in Edit...
Vulnerability Description
Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit ContentData page.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54856
Credits & Attribution
No credits recorded in the NVD database.
References
More from Six Apart Ltd.
View All →Affected Vendor
Six Apart Ltd.
View all reports →