CVE-2026-24447
MEDIUMMovable Type 8.0.2-8.0.8, 8.8.0-8.8.1, 9.0.4-9.0.5 - CSV Injection
Title source: llmDescription
If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
References (3)
Core 3
Core References
Various Sources
https://movabletype.org/news/2026/02/mt-906-released.html
Various Sources
https://www.sixapart.jp/movabletype/news/2026/02/04-1100.html
Third Party Advisory
https://jvn.jp/en/jp/JVN45405689/
Scores
CVSS v3
6.5
EPSS
0.0022
EPSS Percentile
11.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1236
Status
published
Products (14)
Six Apart Ltd./Movable Type (Cloud Edition)
8.8.1 (8 series)
Six Apart Ltd./Movable Type (Cloud Edition)
9.0.5 (9 series)
Six Apart Ltd./Movable Type (Software Edition)
8.0.2 to 8.0.8 (8.0 series)
Six Apart Ltd./Movable Type (Software Edition)
8.8.0 to 8.8.1 (8.8 series)
Six Apart Ltd./Movable Type (Software Edition)
9.0.4 to 9.0.5 (9.0 series)
Six Apart Ltd./Movable Type Advanced (Software Edition)
8.0.2 to 8.0.8 (8.0 series)
Six Apart Ltd./Movable Type Advanced (Software Edition)
8.8.0 to 8.8.1 (8.8 series)
Six Apart Ltd./Movable Type Advanced (Software Edition)
9.0.4 to 9.0.5 (9.0 series)
Six Apart Ltd./Movable Type Premium (Advanced Edition) (Software Edition)
2.13 and earlier (MTP 2 series)
Six Apart Ltd./Movable Type Premium (Advanced Edition) (Software Edition)
9.0.4 (MTP 9.0 series)
... and 4 more
Published
Feb 04, 2026
Tracked Since
Feb 18, 2026