CVE-2026-21393: XSS
Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21393?
CVE-2026-21393 is classified as a high-severity stored cross-site scripting vulnerability.
How do I fix CVE-2026-21393?
To fix CVE-2026-21393, upgrade to the latest version of Movable Type that is not affected by this vulnerability.
Which versions are affected by CVE-2026-21393?
CVE-2026-21393 affects Movable Type 7.x and 8.4 versions, which are considered End-of-Life.
What types of attacks can be executed due to CVE-2026-21393?
Due to CVE-2026-21393, attackers can execute arbitrary scripts on a logged-in user's web browser.
Is CVE-2026-21393 being actively exploited?
While specific exploitation details are not readily available, the nature of stored XSS vulnerabilities typically poses a significant risk to users.