CNNVD-202602-743 Information
Feb 04, 2026
cve
CNNVD ID
CNNVD-202602-743
Related CVE
- CNNVD Published: 2026-02-04
Description (Chinese)
Movable Type是Movable Type公司的一个内容管理系统。 Movable Type存在跨站脚本漏洞,该漏洞源于编辑评论中存在存储型跨站脚本漏洞,可能导致在已登录用户的Web浏览器上执行任意脚本。
Description (English)
Movable Type is a content management system for Movable Type. Movable Type has a cross-site script loophole, which stems from the existence of a memory-type cross-site script gap in the editor ’ s comments, which may result in the implementation of any script on a login user ’ s Web browser.
Hazard Level
High
Vulnerability Type
跨站脚本
Affected Vendor
Movable Type
Published
2026-02-04
Last Modified
2026-02-24
References
https://jvn.jp/en/jp/JVN45405689/ https://www.sixapart.jp/movabletype/news/2026/02/04-1100.html https://movabletype.org/news/2026/02/mt-906-released.html https://access.redhat.com/security/cve/cve-2026-21393
Patch
https://movabletype.org/news/2026/02/mt-906-released.html
Share on: