CVE-2026-23704
Unknown
Unknown - Not Provided
Stored XSS via Malicious File Upload in Movable Type Admin Panel
Publication date: 2026-02-04
Last updated on: 2026-02-04
Assigner: JPCERT/CC
Description
Description
A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| movable_type | movable_type | 7 |
| movable_type | movable_type | 8.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |