CVE-2026-33088: Sixapart Movable Type
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.
Affected products
- Sixapart Movable Type: from 8.0.2, before 8.0.10 (fixed in 8.0.10); from 8.8.0, before 8.8.3 (fixed in 8.8.3); from 9.0.1, before 9.0.7 (fixed in 9.0.7); version 9.1.0 only; up to and including 2.14; version 9.0.5 only; …
Published 2026-04-08. Last modified 2026-07-24.