Stored Cross-Site Scripting Vulnerability in Movable Type by Six Apart
CVE-2025-24841
What is CVE-2025-24841?
Movable Type has a stored cross-site scripting vulnerability in the HTML edit mode of the MT Block Editor. This vulnerability can be exploited specifically when the TinyMCE6 rich text editor is utilized, allowing an attacker to execute arbitrary scripts in the web browser of a logged-in user. This can lead to unauthorized actions or data exposure, making it critical for users of affected versions to promptly address this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Movable Type (8.0.x series) 8.0.5 and earlier
Movable Type (8.4.x series) 8.4.1 and earlier
Movable Type Advanced (8.0.x series) 8.0.5 and earlier
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
