movable_type_premium_cloud_edition vulnerabilities
CVEs whose affected-version data names the movable_type_premium_cloud_edition package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-96408Critical· 9.4A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
▾ MidnightSix Apart Ltd. · Movable Type Cloud Editionvia NVD
CVE-2026-103668High· 8.6An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.
An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.
▾ TwilightSix Apart Ltd. · Movable Type Cloud Editionvia NVD