CVE-2026-22875: XSS
Movable Type contains a stored cross-site scripting vulnerability in Export Sites. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22875?
CVE-2026-22875 is classified as a stored cross-site scripting vulnerability, which can lead to significant security issues if exploited.
How do I fix CVE-2026-22875?
To address CVE-2026-22875, update Movable Type to the latest version that is not affected, as the vulnerable versions are 7.x and 8.4 series which are End-of-Life.
Who is affected by CVE-2026-22875?
Users of Movable Type versions 7 and 8.4 are affected by CVE-2026-22875, particularly those who utilize the Export Sites feature.
What kind of attack can CVE-2026-22875 enable?
CVE-2026-22875 can allow an attacker to execute arbitrary scripts in the web browser of a logged-in user through stored malicious input.
Is there a patch available for CVE-2026-22875?
No official patch is available for CVE-2026-22875 as the affected versions are End-of-Life, so migration to a newer supported version is recommended.