CVE-2014-0977
Sixapart Movabletype - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5.2.9, and 6.0.x before 6.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References (10)
Scores
EPSS
0.0060
EPSS Percentile
69.4%
Details
CWE
CWE-79
Status
published
Products (18)
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
sixapart/movabletype
... and 8 more
Published
Jan 10, 2014
Tracked Since
Feb 18, 2026