Not a developer? Go to MovableType.com

Documentation

Movable Type 8.0.13 Release Notes

This version of Movable Type was released October 7, 2026.

This release addresses issues found in Movable Type 8.0.12.

New and improved features

  • Added and updated the bundled CPAN modules in extlib (MTC-31615)
    • [Updated] Crypt::URandom (0.36 → 0.55)
    • [Updated] HTTP::Daemon (6.14 → 6.17)
    • [Updated] HTTP::Date (6.05 → 6.08)
    • [Updated] Image::ExifTool (12.50 → 13.55)
    • [Updated] LWP::Protocol::https (6.10 → 6.15)
    • [Updated] Net::OAuth (0.28 → 0.31)
    • [Updated] libwww-perl (6.67 → 6.83)

Dynamic Publishing

  • Updated the bundled version of Smarty from 4.5.5 to 4.5.7 (MTC-31542)

Resolved issues

Security fixes and improvements

  • Fixed an issue where CSRF token checks were not performed for the “Publish” and “Unpublish” actions on listing screens such as the Entry listing screen (MTC-31366)
  • Fixed a potential OS command injection vulnerability in the run-periodic-tasks script (MTC-31369)
  • Fixed a cross-site scripting (XSS) vulnerability in the restore upload dialog (MTC-31373)
  • Fixed an arbitrary code execution (RCE) vulnerability in the sort_method modifier of the MTSubCategories tag (MTC-31374)
  • Fixed an arbitrary code execution (RCE) vulnerability during restore upload (MTC-31375)
  • Fixed a potential remote code execution (RCE) vulnerability in Dynamic Publishing (MTC-31384)
  • Fixed a cross-site scripting (XSS) vulnerability on the ContentType selection screen (MTC-31385)
  • Fixed a cross-site scripting (XSS) vulnerability on the Rebuild Trigger settings screen (MTC-31386)
  • Fixed a cross-site scripting (XSS) vulnerability on the ContentType Archive Mapping settings screen (MTC-31387)
  • Fixed a cross-site scripting (XSS) vulnerability in the module modifier of the MTInclude tag on the template editing screen (MTC-31383)
  • Fixed a cross-site scripting (XSS) vulnerability in the blog_id modifier of the MTInclude tag on the template editing screen (MTC-31388)
  • Fixed a cross-site scripting (XSS) vulnerability on the ContentData editing and listing screens (MTC-31389)
  • Fixed a cross-site scripting (XSS) vulnerability in the Table field of ContentData (MTC-31390)
  • Fixed a cross-site scripting (XSS) vulnerability in the “Embedded Text” field of ContentData (MTC-31391)
  • Fixed a cross-site scripting (XSS) vulnerability on the template initialization (refresh) screen (MTC-31392)
  • Fixed a cross-site scripting (XSS) vulnerability that occurred when importing specially crafted export data (MTC-31393)
  • Fixed a cross-site scripting (XSS) vulnerability when outputting the MTSearchContentTypes tag in the ContentData search results template (MTC-31394)
  • Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 settings on the Web Services settings screen (MTC-31395)
  • Fixed a cross-site scripting (XSS) vulnerability in the asset selection dialog of the legacy Block Editor (MTC-31396)
  • Fixed a cross-site scripting (XSS) vulnerability in the Image block of the legacy Block Editor (MTC-31397)
  • Fixed a cross-site scripting (XSS) vulnerability in the bulk user import feature and on the LDAP integration settings screen (MTC-31406)
  • Fixed an issue where insufficient CSRF token validation in the Search and Replace feature could cause Entry content to be unintentionally replaced or deleted (MTC-31407)
  • Fixed an issue where insufficient CSRF token checks in the asset information update endpoints allowed item information to be updated unintentionally (MTC-31410)
  • Fixed an issue in Dynamic Publishing that could lead to arbitrary code execution (RCE) through the min_score modifier of the MTEntries tag (MTC-31415)
  • Fixed an issue in the WXR file import feature that could allow arbitrary files to be written under the site path (MTC-31416)
  • Fixed an issue where invalid SQL could be executed through searches in the Admin screen (MTC-31417)
  • Fixed missing permission checks in the template duplication process (MTC-31418)
  • Fixed missing permission checks in the asset editing and saving processes (MTC-31419)
  • Fixed missing permission checks in the category and folder move processes (MTC-31420)
  • Fixed missing permission checks in the bulk update process for Category Sets (MTC-31421)
  • Fixed missing permission checks in the “Refresh” action on the template listing screen (MTC-31422)
  • Fixed missing permission checks in the folder move process (MTC-31423)
  • Fixed missing permission checks in the asset upload cancellation process (MTC-31424)
  • Fixed missing permission checks in the endpoint for directly inserting assets (MTC-31425)
  • Fixed an issue where the permission check for editing site settings could be bypassed in the generic save process, allowing the Publishing Profile to be changed (MTC-31427)
  • Fixed an issue with the order of permission checks on the rebuild start page (MTC-31429)
  • Fixed an issue in the Data API stats-related endpoints where users without site permissions could access analytics provider access information (MTC-31430)
  • Fixed missing permission checks in the ContentType save process (MTC-31431)
  • Fixed missing permission checks in the save and delete processes for banned IP addresses (BanList) (MTC-31432)
  • Fixed missing permission checks in the Rebuild Trigger save process (MTC-31434)
  • Fixed an issue where the primary category ID of another site could be specified when saving an Entry (MTC-31435)
  • Fixed missing permission checks in the user profile image selection process (MTC-31436)
  • Fixed an issue in site search (mt-search.cgi) where malicious SQL could be executed, potentially exposing data including unpublished data (MTC-31457/CVE-2026-103668)
  • Fixed an issue where an internal redirect could redirect users to a malicious URL when token validation failed and prompted them to sign in again (MTC-31459)
  • Fixed an issue where session invalidation checks for session information retrieved from cookies and other sources were insufficient, potentially allowing users to sign in with an invalidated session ID (MTC-31463)
  • Fixed an issue where CSRF token checks were not performed for various list actions, including duplicating and refreshing templates and unpublishing ContentData (MTC-31495)
  • Fixed an issue in the WXR attachment import feature that could allow file contents to be read (MTC-31510)
  • Fixed a cross-site scripting (XSS) vulnerability on the filter listing screen in the Listing Framework (MTC-31534)
  • Fixed a cross-site scripting (XSS) vulnerability on the asset listing screen (MTC-31535)
  • Fixed a cross-site scripting (XSS) vulnerability in the analytics snippet output (MTStatsSnippet tag) of the Google Analytics 4 plugin (MTC-31536)
  • Fixed a cross-site scripting (XSS) vulnerability in the tag autocomplete feature for Entries and other objects (MTC-31537)
  • Fixed a cross-site scripting (XSS) vulnerability in the asset selection modal of the legacy BlockEditor plugin (MTC-31538)
  • Enhanced validation to prevent control characters and disallowed domain formats from being entered in the “Site URL” and “Archive URL” fields when creating a site or changing site settings (MTC-31540)
  • Fixed a cross-site scripting (XSS) vulnerability on the theme export screen (MTC-31562)
  • Fixed a cross-site scripting (XSS) vulnerability on the rebuild completion pop-up screen (MTC-31563)
  • Fixed a cross-site scripting (XSS) vulnerability in the Listing Framework (MTC-31569)
  • Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 plugin (MTC-31594)
  • Fixed an issue in the upgrade script (mt-upgrade.cgi) that could allow remote code execution (RCE) or malicious SQL execution (MTC-31703/CVE-2026-96408)

Acknowledgments

We would like to thank everyone for their contributions to this release, especially those who reported these issues and vulnerabilities. We would also like to thank JPCERT/CC and IPA for their assistance in handling the vulnerability information.

  • RyotaK, GMO Flatt Security Inc. (MTC-31457/CVE-2026-103668, MTC-31703/CVE-2026-96408)

Checksums

Back