CVE-2025-22888: Six Apart Ltd Movable Type 8.0.x Series
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If exploited, an arbitrary script may be executed on a logged-in user's web browser.
Affected products
- Six Apart Ltd Movable Type 8.0.x Series: up to and including 8.0.5
- Six Apart Ltd Movable Type 8.4.x Series: up to and including 8.4.1
- Six Apart Ltd Movable Type Advanced 8.0.x Series: up to and including 8.0.5
- Six Apart Ltd Movable Type Advanced 8.4.x Series: up to and including 8.4.1
- Six Apart Ltd Movable Type Cloud Edition 8.x Series: up to and including 8.4.1
- Six Apart Ltd Movable Type Premium 2.x Series: up to and including 2.06
- Six Apart Ltd Movable Type Premium Advanced Edition 2.x Series: up to and including 2.06
- Six Apart Ltd Movable Type Premium Cloud Edition 2.x Series: up to and including 2.06
Published 2025-02-19. Last modified 2026-06-17.