CVE-2026-44392 describes a missing authorization weakness in Movable Type. According to the published summary, under certain conditions a user without administrator privileges signing in to the product can trigger unintended update processing. The issue is rated CVSS 5.3 (Medium) and maps to CWE-862 (Missing Authorization).
PatchSiren has analyzed CVE-2026-33088, an SQL Injection vulnerability in Movable Type by Six Apart Ltd. This vulnerability may allow an attacker to execute an arbitrary SQL statement. The CVE record was published on 2026-04-08T09:16:21.213Z and has not been modified since then. The vulnerability has a CVSS score of 6.9, indicating a medium severity level. Users of Movable Type should review and apply pat [truncated]