CVE-2015-0845: Sixapart Movabletype

High severity, CVSS 7.5. EPSS: 3.7% chance of exploitation in the next 30 days.

Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.

Affected products

  • Sixapart Movabletype: up to and including 5.2.11; version 6.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; …

Published 2015-04-17. Last modified 2026-06-17.