Vulnerabilities > Sixapart > Movabletype > High

DATE CVE VULNERABILITY TITLE RISK
2015-04-17 CVE-2015-0845 Code Injection vulnerability in Sixapart Movabletype
Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.
network
low complexity
sixapart CWE-94
7.5
2010-12-09 CVE-2010-3922 SQL Injection vulnerability in Sixapart Movabletype
SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
sixapart CWE-89
7.5