🔐 CVE Alert

CVE-2026-103668

HIGH 8.6
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.

Vendor six apart ltd.
Product movable type cloud edition
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for six apart ltd. movable type cloud edition

Be the first to know when new high vulnerabilities affecting six apart ltd. movable type cloud edition are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Affected Versions

Six Apart Ltd. / Movable Type Cloud Edition
9.2.0 ≤ 9.2.1
Six Apart Ltd. / Movable Type
9.0.0 ≤ 9.0.9 8.8.0 ≤ 8.8.5 8.0.0 ≤ 8.0.12
Six Apart Ltd. / Movable Type Premium Cloud Edition
9.2.0 ≤ 9.2.1
Six Apart Ltd. / Movable Type Premium
9.0.0 ≤ 9.0.9 2.0 ≤ 2.17

References

NVD ↗ CVE.org ↗ EPSS Data ↗
movabletype.org: https://movabletype.org/news/2026/10/mt-930-released.html sixapart.jp: https://www.sixapart.jp/movabletype/news/2026/10/07-1100.html jvn.jp: https://jvn.jp/en/jp/JVN91153973/