CVE-2025-22888: XSS
Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be executed on a logged-in user's web browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22888?
CVE-2025-22888 is categorized as a stored cross-site scripting vulnerability with a significant potential impact on user security.
How do I fix CVE-2025-22888?
To fix CVE-2025-22888, update Movable Type to the latest version where the vulnerability has been patched.
What software is affected by CVE-2025-22888?
CVE-2025-22888 affects versions of Movable Type developed by Six Apart.
What impact does CVE-2025-22888 have if exploited?
Exploitation of CVE-2025-22888 could allow an attacker to execute arbitrary scripts in the web browsers of logged-in users.
Is CVE-2025-22888 a local or remote attack?
CVE-2025-22888 represents a remote attack vector since it targets actions performed by logged-in users through the web application.