PT-2026-107472 · Six Apart · Movable Type+3

CVE-2026-103668

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103668

Affected Products

Movable Type
Movable Type Cloud Edition
Movable Type Premium
Movable Type Premium Cloud Edition