{"id":"CVE-2026-33088","title":"Movable Type provided by Six Apart Ltd","summary":"Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-89"],"vendor":"sixapart","product":"movable_type","affected":["movable_type >= 8.0.2, < 8.0.10","movable_type >= 8.8.0, < 8.8.3","movable_type >= 9.0.1, < 9.0.7","movable_type = 9.1.0","movable_type <= 2.14","movable_type = 9.0.5","movable_type = 9.0.6"],"patched":["movable_type 9.0.7"],"published":"2026-04-08","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33088","references":[{"url":"https://jvn.jp/en/jp/JVN66473735/","label":"vultures@jpcert.or.jp"},{"url":"https://movabletype.org/news/2026/04/mt-907-released.html","label":"vultures@jpcert.or.jp"},{"url":"https://www.sixapart.jp/movabletype/news/2026/04/08-1100.html","label":"vultures@jpcert.or.jp"}],"tags":["nvd"],"epss":0.00349,"epssPercentile":0.28654,"ingestedAt":"2026-07-25T23:05:59.179Z","slug":"CVE-2026-33088","body":"## Overview\n\nMovable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.\n\n## Affected\n\n- `movable_type >= 8.0.2, < 8.0.10`\n- `movable_type >= 8.8.0, < 8.8.3`\n- `movable_type >= 9.0.1, < 9.0.7`\n- `movable_type = 9.1.0`\n- `movable_type <= 2.14`\n- `movable_type = 9.0.5`\n- `movable_type = 9.0.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `movable_type 9.0.7`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}