CVE-2026-103668: Six Apart Ltd Movable Type

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.

Affected products

  • Six Apart Ltd Movable Type: from 9.0.0, up to and including 9.0.9; from 8.8.0, up to and including 8.8.5; from 8.0.0, up to and including 8.0.12
  • Six Apart Ltd Movable Type Cloud Edition: from 9.2.0, up to and including 9.2.1
  • Six Apart Ltd Movable Type Premium: from 9.0.0, up to and including 9.0.9; from 2.0, up to and including 2.17
  • Six Apart Ltd Movable Type Premium Cloud Edition: from 9.2.0, up to and including 9.2.1

Published 2026-10-07. Last modified 2026-10-07.