Six Apart Ltd. has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 9.0 (critical), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.0
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-96408Critical· 9.4A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.52CVE-2026-103668High· 8.6An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.47
Six Apart Ltd. vulnerabilities
CVEs affecting Six Apart Ltd., newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-96408Critical· 9.4A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
▾ MidnightSix Apart Ltd. · Movable Type Cloud Editionvia NVD
CVE-2026-103668High· 8.6An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.
An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.
▾ TwilightSix Apart Ltd. · Movable Type Cloud Editionvia NVD