CVE-2026-33088

Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:advanced:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:sixapart:movable_type:*:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.0.5:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.0.6:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:premium_advanced:*:*:*

History

No history.

Information

Published : 2026-04-08 09:16

Updated : 2026-07-24 23:10


NVD link : CVE-2026-33088

Mitre link : CVE-2026-33088

CVE.ORG link : CVE-2026-33088


JSON object : View

Products Affected

sixapart

  • movable_type
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')