216.73.217.22

CVE-2026-23704

· Published 04/02/2026 07:16 · Modified 04/02/2026 16:33

Labels: CVE-2026-23704 2026-02-04CVE-2026-23704CWE-434[email protected]

Essential information

Published
04/02/2026 07:16
Modified
04/02/2026 16:33
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
movable type / movable type cpe:2.3:a:movable_type:movable_type:*:*:*:*:*:*:*:*
movable type / movable type cpe:2.3:a:movable_type:movable_type:7:*:*:*:*:*:*:*
movable type / movable type cpe:2.3:a:movable_type:movable_type:8.4:*:*:*:*:*:*:*

References