Movable Type 8.0.13 Release Notes
This version of Movable Type was released October 7, 2026.
This release addresses issues found in Movable Type 8.0.12.
New and improved features
- Added and updated the bundled CPAN modules in
extlib(MTC-31615)
- [Updated]
Crypt::URandom(0.36 → 0.55) - [Updated]
HTTP::Daemon(6.14 → 6.17) - [Updated]
HTTP::Date(6.05 → 6.08) - [Updated]
Image::ExifTool(12.50 → 13.55) - [Updated]
LWP::Protocol::https(6.10 → 6.15) - [Updated]
Net::OAuth(0.28 → 0.31) - [Updated]
libwww-perl(6.67 → 6.83)
- [Updated]
Dynamic Publishing
- Updated the bundled version of Smarty from 4.5.5 to 4.5.7 (MTC-31542)
Resolved issues
Security fixes and improvements
- Fixed an issue where CSRF token checks were not performed for the “Publish” and “Unpublish” actions on listing screens such as the Entry listing screen (MTC-31366)
- Fixed a potential OS command injection vulnerability in the
run-periodic-tasksscript (MTC-31369) - Fixed a cross-site scripting (XSS) vulnerability in the restore upload dialog (MTC-31373)
- Fixed an arbitrary code execution (RCE) vulnerability in the
sort_methodmodifier of theMTSubCategoriestag (MTC-31374) - Fixed an arbitrary code execution (RCE) vulnerability during restore upload (MTC-31375)
- Fixed a potential remote code execution (RCE) vulnerability in Dynamic Publishing (MTC-31384)
- Fixed a cross-site scripting (XSS) vulnerability on the ContentType selection screen (MTC-31385)
- Fixed a cross-site scripting (XSS) vulnerability on the Rebuild Trigger settings screen (MTC-31386)
- Fixed a cross-site scripting (XSS) vulnerability on the ContentType Archive Mapping settings screen (MTC-31387)
- Fixed a cross-site scripting (XSS) vulnerability in the
modulemodifier of theMTIncludetag on the template editing screen (MTC-31383) - Fixed a cross-site scripting (XSS) vulnerability in the
blog_idmodifier of theMTIncludetag on the template editing screen (MTC-31388) - Fixed a cross-site scripting (XSS) vulnerability on the ContentData editing and listing screens (MTC-31389)
- Fixed a cross-site scripting (XSS) vulnerability in the Table field of ContentData (MTC-31390)
- Fixed a cross-site scripting (XSS) vulnerability in the “Embedded Text” field of ContentData (MTC-31391)
- Fixed a cross-site scripting (XSS) vulnerability on the template initialization (refresh) screen (MTC-31392)
- Fixed a cross-site scripting (XSS) vulnerability that occurred when importing specially crafted export data (MTC-31393)
- Fixed a cross-site scripting (XSS) vulnerability when outputting the
MTSearchContentTypestag in the ContentData search results template (MTC-31394) - Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 settings on the Web Services settings screen (MTC-31395)
- Fixed a cross-site scripting (XSS) vulnerability in the asset selection dialog of the legacy Block Editor (MTC-31396)
- Fixed a cross-site scripting (XSS) vulnerability in the Image block of the legacy Block Editor (MTC-31397)
- Fixed a cross-site scripting (XSS) vulnerability in the bulk user import feature and on the LDAP integration settings screen (MTC-31406)
- Fixed an issue where insufficient CSRF token validation in the Search and Replace feature could cause Entry content to be unintentionally replaced or deleted (MTC-31407)
- Fixed an issue where insufficient CSRF token checks in the asset information update endpoints allowed item information to be updated unintentionally (MTC-31410)
- Fixed an issue in Dynamic Publishing that could lead to arbitrary code execution (RCE) through the
min_scoremodifier of theMTEntriestag (MTC-31415) - Fixed an issue in the WXR file import feature that could allow arbitrary files to be written under the site path (MTC-31416)
- Fixed an issue where invalid SQL could be executed through searches in the Admin screen (MTC-31417)
- Fixed missing permission checks in the template duplication process (MTC-31418)
- Fixed missing permission checks in the asset editing and saving processes (MTC-31419)
- Fixed missing permission checks in the category and folder move processes (MTC-31420)
- Fixed missing permission checks in the bulk update process for Category Sets (MTC-31421)
- Fixed missing permission checks in the “Refresh” action on the template listing screen (MTC-31422)
- Fixed missing permission checks in the folder move process (MTC-31423)
- Fixed missing permission checks in the asset upload cancellation process (MTC-31424)
- Fixed missing permission checks in the endpoint for directly inserting assets (MTC-31425)
- Fixed an issue where the permission check for editing site settings could be bypassed in the generic save process, allowing the Publishing Profile to be changed (MTC-31427)
- Fixed an issue with the order of permission checks on the rebuild start page (MTC-31429)
- Fixed an issue in the Data API stats-related endpoints where users without site permissions could access analytics provider access information (MTC-31430)
- Fixed missing permission checks in the ContentType save process (MTC-31431)
- Fixed missing permission checks in the save and delete processes for banned IP addresses (
BanList) (MTC-31432) - Fixed missing permission checks in the Rebuild Trigger save process (MTC-31434)
- Fixed an issue where the primary category ID of another site could be specified when saving an Entry (MTC-31435)
- Fixed missing permission checks in the user profile image selection process (MTC-31436)
- Fixed an issue in site search (
mt-search.cgi) where malicious SQL could be executed, potentially exposing data including unpublished data (MTC-31457/CVE-2026-103668) - Fixed an issue where an internal redirect could redirect users to a malicious URL when token validation failed and prompted them to sign in again (MTC-31459)
- Fixed an issue where session invalidation checks for session information retrieved from cookies and other sources were insufficient, potentially allowing users to sign in with an invalidated session ID (MTC-31463)
- Fixed an issue where CSRF token checks were not performed for various list actions, including duplicating and refreshing templates and unpublishing ContentData (MTC-31495)
- Fixed an issue in the WXR attachment import feature that could allow file contents to be read (MTC-31510)
- Fixed a cross-site scripting (XSS) vulnerability on the filter listing screen in the Listing Framework (MTC-31534)
- Fixed a cross-site scripting (XSS) vulnerability on the asset listing screen (MTC-31535)
- Fixed a cross-site scripting (XSS) vulnerability in the analytics snippet output (
MTStatsSnippettag) of the Google Analytics 4 plugin (MTC-31536) - Fixed a cross-site scripting (XSS) vulnerability in the tag autocomplete feature for Entries and other objects (MTC-31537)
- Fixed a cross-site scripting (XSS) vulnerability in the asset selection modal of the legacy BlockEditor plugin (MTC-31538)
- Enhanced validation to prevent control characters and disallowed domain formats from being entered in the “Site URL” and “Archive URL” fields when creating a site or changing site settings (MTC-31540)
- Fixed a cross-site scripting (XSS) vulnerability on the theme export screen (MTC-31562)
- Fixed a cross-site scripting (XSS) vulnerability on the rebuild completion pop-up screen (MTC-31563)
- Fixed a cross-site scripting (XSS) vulnerability in the Listing Framework (MTC-31569)
- Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 plugin (MTC-31594)
- Fixed an issue in the upgrade script (
mt-upgrade.cgi) that could allow remote code execution (RCE) or malicious SQL execution (MTC-31703/CVE-2026-96408)
Acknowledgments
We would like to thank everyone for their contributions to this release, especially those who reported these issues and vulnerabilities. We would also like to thank JPCERT/CC and IPA for their assistance in handling the vulnerability information.
- RyotaK, GMO Flatt Security Inc. (MTC-31457/CVE-2026-103668, MTC-31703/CVE-2026-96408)