PatchSiren

Six Apart Ltd. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Six Apart Ltd. CVE published 2026-05-20

CVE-2026-44392

CVE-2026-44392 describes a missing authorization weakness in Movable Type. According to the published summary, under certain conditions a user without administrator privileges signing in to the product can trigger unintended update processing. The issue is rated CVSS 5.3 (Medium) and maps to CWE-862 (Missing Authorization).

MEDIUM Six Apart Ltd. CVE published 2026-04-08

CVE-2026-33088

PatchSiren has analyzed CVE-2026-33088, an SQL Injection vulnerability in Movable Type by Six Apart Ltd. This vulnerability may allow an attacker to execute an arbitrary SQL statement. The CVE record was published on 2026-04-08T09:16:21.213Z and has not been modified since then. The vulnerability has a CVSS score of 6.9, indicating a medium severity level. Users of Movable Type should review and apply pat [truncated]