CVE-2025-24841: XSS
Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as a rich text editor and an arbitrary script may be executed on a logged-in user's web browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24841?
CVE-2025-24841 is classified as a high severity vulnerability due to its impact on user sessions through stored cross-site scripting.
How do I fix CVE-2025-24841?
To fix CVE-2025-24841, you should update to the latest version of Movable Type that addresses this vulnerability.
Who is affected by CVE-2025-24841?
CVE-2025-24841 affects users of Movable Type when using TinyMCE6 as a rich text editor.
What type of vulnerability is CVE-2025-24841?
CVE-2025-24841 is a stored cross-site scripting vulnerability.
Can CVE-2025-24841 be exploited remotely?
Yes, CVE-2025-24841 can be exploited remotely by executing an arbitrary script on a logged-in user's web browser.