CVE-2026-33088

Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:advanced:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:sixapart:movable_type:*:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.0.5:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.0.6:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:premium_advanced:*:*:*

History

20 Apr 2026, 17:20

Type Values Removed Values Added
CPE cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:*:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.0.6:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.0.5:*:*:*:premium_advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:advanced:*:*:*
cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:premium_advanced:*:*:*
First Time Sixapart
Sixapart movable Type
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 9.8
References () https://jvn.jp/en/jp/JVN66473735/ - () https://jvn.jp/en/jp/JVN66473735/ - Third Party Advisory
References () https://movabletype.org/news/2026/04/mt-907-released.html - () https://movabletype.org/news/2026/04/mt-907-released.html - Vendor Advisory
References () https://www.sixapart.jp/movabletype/news/2026/04/08-1100.html - () https://www.sixapart.jp/movabletype/news/2026/04/08-1100.html - Vendor Advisory

08 Apr 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 09:16

Updated : 2026-04-20 17:20


NVD link : CVE-2026-33088

Mitre link : CVE-2026-33088

CVE.ORG link : CVE-2026-33088


JSON object : View

Products Affected

sixapart

  • movable_type
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')