CVE-2010-3921
Sixapart Movabletype - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References (6)
Scores
EPSS
0.0047
EPSS Percentile
64.6%
Classification
CWE
CWE-79
Status
published
Affected Products (18)
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
... and 3 more
Timeline
Published
Dec 09, 2010
Tracked Since
Feb 18, 2026