Not a developer? Go to MovableType.com

Documentation

Movable Type 8.8.6 Release Notes

This version of Movable Type was released October 7, 2026.

This release addresses issues found in Movable Type 8.8.5.

New and improved features

  • Added the archive_type column to the mt_deletefileinfo table to improve the accuracy of file deletion when files associated with specific Entries or ContentData are edited or deleted (MTC-28424)
  • Added the Configuration Directive UseCodeMirror6. Setting it to 1 uses CodeMirror 6 as the code editor on the template editing screen. The default value is 0, which uses CodeMirror 5 (MTC-30846)
  • Added the Configuration Directive MailSMTPOAuthProvider, which specifies the authentication provider to use with OAuth 2.0 for SMTP authentication (MTC-31492)
  • Disabled the License Verification plugin and replaced it with the License Pack add-on (MTC-30730)
  • Added the option to display the log “Level” as a column through Display Options on the System Log listing screen in the Admin screen (MTC-31503)
  • Added and updated the bundled CPAN modules in extlib (MTC-31615)
    • [Updated] CGI (4.71 → 4.72)
    • [Updated] Crypt::URandom (0.54 → 0.55)
    • [Updated] Digest::Perl::MD5 (1.9 → 1.91)
    • [Updated] HTTP::Daemon (6.16 → 6.17)
    • [Updated] HTTP::Date (6.06 → 6.08)
    • [Updated] Image::ExifTool (13.44 → 13.55)
    • [Updated] JSON (4.10 → 4.11)
    • [Updated] JSON::PP (4.16 → 4.18)
    • [Updated] LWP::Protocol::https (6.14 → 6.15)
    • [Updated] MIME::Lite (3.033 → 3.038)
    • [Updated] WWW::RobotRules (6.02 → 6.03)
    • [Updated] TimeDate (2.31 → 2.35)
    • [Updated] URI (5.34 → 5.35)
    • [Updated] libwww-perl (6.81 → 6.83)
    • [Updated] version (0.9933 → 0.9934)

Added and updated plugins

  • Updated the MFA-TOTP plugin to version 1.2.1 (MTC-31588)
  • Updated the MTBlockEditor plugin to version 1.4.0 (MTC-31617)
  • Updated the MTRichTextEditor plugin to version 1.0.6 (MTC-31628)

MFA TOTP plugin

  • Added the autocomplete="one-time-code" attribute to the verification code input field in the MFA-TOTP plugin to improve the autofill experience with password managers and other tools (MTC-31360)

MTRichTextEditor plugin

  • Changed the selection color to translucent so that the content remains visible when a table is selected with the mouse (MTC-31288)
  • Added the ability to specify the border style and color, background color, and other table properties (MTC-31289)
  • Allowed multiple CSS file URLs to be specified as a comma-separated list in the Content CSS File setting (MTC-31372)
  • Enabled the button element by default (MTC-31557)
  • Updated Tiptap from version 3.20.1 to 3.27.1 (MTC-31561)

Dynamic Publishing

  • Added support for PHP 8.5 (MTC-31010)
  • Updated the bundled version of Smarty from 4.5.5 to 4.5.7 (MTC-31542)

Resolved issues

  • Fixed the Use of uninitialized value warning that occurred when the SiteURL Configuration Directive was undefined (CLOUD-581)
  • Fixed a JavaScript error that occurred when navigating between pages in dialogs, such as the permission assignment and rebuild trigger dialogs (MTC-30587)
  • Fixed an issue where the Data Identifier Label setting was reset after repeatedly saving on the ContentType editing screen (MTC-31096)
  • Fixed an issue where the expected warning message was not displayed when viewing a revision containing deleted tags or categories from the revision history of an Entry or Web Page (MTC-31111)
  • Fixed an issue where the contents of unused tag fields were lost when restoring an Entry or Web Page from its revision history (MTC-31117)
  • Changed to display a warning message notifying users that the Data Identifier Label setting was cleared when the required setting was disabled for the assigned field or the field was deleted (MTC-31202)
  • Fixed an issue where sites and child sites continued to appear without links in the left menu of the dashboard after a user’s permissions were removed (MTC-31293)
  • Fixed an error that occurred when filtering the Category Set listing screen by the number of categories or ContentTypes (MTC-31295)
  • Fixed an issue where pagination did not work correctly in the list for selecting target ContentTypes on the Rebuild Trigger settings screen (MTC-31314)
  • Improved the behavior when removing the required setting from or deleting the field configured as the Data Identifier Label on the ContentType editing screen (MTC-31315)
  • Fixed an issue where the format setting for a Text (Multi-Line) field was not applied in the ContentData preview (MTC-31322)
  • Fixed an issue where files were not transferred during server delivery from a Windows environment to another environment, such as Linux, because relative paths were not replaced correctly due to differences in path separators (MTC-31324)
  • Fixed mt-upgrade.cgi and mt-wizard.cgi to refer to AdminCGIPath instead of CGIPath in PSGI environments (MTC-31326)
  • Fixed an issue where buttons extended beyond the window and were not visible in the “View Source Code” modal window of MTBlockEditor using TinyMCE 6 (MTC-31333)
  • Fixed the Use of uninitialized value warning that occurred when sorting a blog list, such as on the System Log listing screen, when the blog ID was undefined (MTC-31340)
  • Fixed an issue where themes placed under the directory specified by the UserThemesDirectory Configuration Directive did not appear on the theme listing screen and could not be applied (MTC-31343)
  • Fixed an issue where the pre_delete_archive_file and post_delete_archive_file callbacks were not called correctly when deleting archive files if the DeleteFilesAfterRebuild Configuration Directive was set to a true value (MTC-31356)
  • Fixed a performance issue when sorting the ContentData listing screen by a ContentField such as the Data Identifier Label (MTC-31400)
  • Fixed an issue where categories were not output in the order shown in the Admin screen when using the MTSubCategories tag inside the MTContentField tag (MTC-31469)
  • Fixed an issue in Movable Type 8.8.x where the “Set up access statistics” link in Site Settings was hidden (MTC-31502)
  • Fixed an issue in PSGI environments where the values of filter fields (select boxes) in the Admin screen were cached in the language used during the initial access, preventing the display language from switching correctly (MTC-31507)
  • Fixed an issue where the process of adding missing default templates during an upgrade generated an excessively large SQL query, which could cause an error in SQL Server (MTC-31520)
  • Fixed an issue where archive files could be unintentionally deleted during ContentData updates because processing was performed with an incorrect combination of category and template mapping (MTC-31522)
  • Fixed an issue where the contents of the first field entered were lost when creating a new Entry or Web Page in rich text format, alternately entering content in the “Body” and “Extended” fields, and then saving (MTC-31595)
  • Fixed an issue where a database error prevented the upgrade from proceeding when a user other than a System administrator was logged in during a version upgrade requiring a schema upgrade (MTC-31598)
  • Changed the conditions under which images from child sites are displayed in the asset list when inserting an image on the Entry editing screen of a parent site or similar screens. Use the RequireAdministerSiteForChildAssets Configuration Directive to restore the previous behavior for backward compatibility (MTC-31517)

MTBlockEditor

  • Improved MTBlockEditor to use a more generic approach in areas that previously depended on the mt:command attribute (MTC-31614)

MTRichTextEditor

  • Changed MTRichTextEditor to add border="1" and style="border-collapse: collapse" by default when inserting a table from the toolbar (MTC-31332)
  • Fixed an issue where styles from Content CSS files were not applied in the boilerplate insertion modal in MTRichTextEditor (MTC-31166)
  • Fixed an issue where the id and class attributes of table elements could not be edited correctly in the “HTML Structure Editing Mode” of MTRichTextEditor (MTC-31290)
  • Fixed an issue where unnecessary line breaks and spaces were inserted when a ruby tag was used in the HTML editing mode of MTRichTextEditor, then HTML editing mode was reopened and the content was saved (MTC-31497)
  • Fixed an issue where either the text color or background color was reset when both were set and saved in MTRichTextEditor (MTC-31552)
  • Fixed an issue where unnecessary mt-text-block elements were inserted into the editor DOM when saving from HTML editing mode in MTRichTextEditor (MTC-31555)
  • Fixed an issue where the results of using the increase and decrease indent buttons were not preserved correctly, and unnecessary data-mt-indent attributes were added in MTRichTextEditor (MTC-31556)
  • Fixed an issue in the inline mode of MTRichTextEditor, where the top toolbar is hidden, that caused the link editing toolbars to overlap and become unusable (MTC-31558)
  • Adjusted the position and stacking order (z-index) of the contextual toolbar when editing links in MTRichTextEditor, fixing an issue where it was hidden behind the menu bar and became unusable (MTC-31613)
  • Fixed an issue on the “System > Rich Text Editor Settings” screen in the Admin screen where rearranging buttons by drag and drop caused duplicate data to be saved, preventing the screen from being displayed (MTC-31622)
  • Fixed an issue where the layout of the editing area was changed by the Content CSS settings (MTC-31667)
  • Enhanced validation of data retrieved from external sites when embedding Web Pages to allow only the http and https schemes (MTC-31413)
  • Fixed HTML editing mode to prevent entered i, b, strike, and del elements from being automatically converted to other elements (MTC-31698)
  • Fixed an issue in HTML editing mode where a div element entered directly under a dd element was unintentionally removed when saved (MTC-31697)

Movable Type Advanced

  • Fixed an issue in SQL Server where an error occurred when adding a column without a default value during an upgrade (MTC-31532)

Dynamic Publishing

  • Improved SQL query construction in Dynamic Publishing (MTC-31304)
  • Fixed an issue where the “Dynamic Publishing Error” template was not displayed correctly when accessing a nonexistent URL while using Dynamic Publishing, and the browser’s default error page was displayed instead (MTC-31334)
  • Fixed an issue in Dynamic Publishing where an Invalid tag filter error occurred when a tag name contained regular expression special characters such as / (MTC-31380)

Security fixes and improvements

  • Fixed an issue where CSRF token checks were not performed for the “Publish” and “Unpublish” actions on listing screens such as the Entry listing screen (MTC-31366)
  • Fixed a potential OS command injection vulnerability in the run-periodic-tasks script (MTC-31369)
  • Fixed a cross-site scripting (XSS) vulnerability in the restore upload dialog (MTC-31373)
  • Fixed an arbitrary code execution (RCE) vulnerability in the sort_method modifier of the MTSubCategories tag (MTC-31374)
  • Fixed an arbitrary code execution (RCE) vulnerability during restore upload (MTC-31375)
  • Fixed a potential remote code execution (RCE) vulnerability in Dynamic Publishing (MTC-31384)
  • Fixed a cross-site scripting (XSS) vulnerability on the ContentType selection screen (MTC-31385)
  • Fixed a cross-site scripting (XSS) vulnerability on the Rebuild Trigger settings screen (MTC-31386)
  • Fixed a cross-site scripting (XSS) vulnerability on the ContentType Archive Mapping settings screen (MTC-31387)
  • Fixed a cross-site scripting (XSS) vulnerability in the module modifier of the MTInclude tag on the template editing screen (MTC-31383)
  • Fixed a cross-site scripting (XSS) vulnerability in the blog_id modifier of the MTInclude tag on the template editing screen (MTC-31388)
  • Fixed a cross-site scripting (XSS) vulnerability on the ContentData editing and listing screens (MTC-31389)
  • Fixed a cross-site scripting (XSS) vulnerability in the Table field of ContentData (MTC-31390)
  • Fixed a cross-site scripting (XSS) vulnerability in the “Embedded Text” field of ContentData (MTC-31391)
  • Fixed a cross-site scripting (XSS) vulnerability on the template initialization (refresh) screen (MTC-31392)
  • Fixed a cross-site scripting (XSS) vulnerability that occurred when importing specially crafted export data (MTC-31393)
  • Fixed a cross-site scripting (XSS) vulnerability when outputting the MTSearchContentTypes tag in the ContentData search results template (MTC-31394)
  • Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 settings on the Web Services settings screen (MTC-31395)
  • Fixed a cross-site scripting (XSS) vulnerability in the asset selection dialog of the legacy Block Editor (MTC-31396)
  • Fixed a cross-site scripting (XSS) vulnerability in the Image block of the legacy Block Editor (MTC-31397)
  • Fixed a cross-site scripting (XSS) vulnerability on the “Basic Authentication Management” screen in the Cloud Edition (MTC-31401)
  • Fixed a cross-site scripting (XSS) vulnerability on the “Domain Settings” screen in the Cloud Edition (MTC-31402)
  • Fixed a cross-site scripting (XSS) vulnerability on the “Web Server Settings” screen in the Cloud Edition (MTC-31403)
  • Fixed a cross-site scripting (XSS) vulnerability on the “Access Restriction Settings” screen in the Cloud Edition (MTC-31404)
  • Fixed a cross-site scripting (XSS) vulnerability in the system security settings of the Cloud Edition (MTC-31405)
  • Fixed a cross-site scripting (XSS) vulnerability in the bulk user import feature and on the LDAP integration settings screen (MTC-31406)
  • Fixed an issue where insufficient CSRF token validation in the Search and Replace feature could cause Entry content to be unintentionally replaced or deleted (MTC-31407)
  • Fixed an issue where insufficient CSRF token checks in the asset information update endpoints allowed item information to be updated unintentionally (MTC-31410)
  • Fixed an issue in the redirect settings of the Cloud Edition where processing continued even when CSRF token validation failed (MTC-31411)
  • Fixed an issue in the web server settings of the Cloud Edition where processing continued even when CSRF token validation failed (MTC-31412)
  • Fixed an issue in Dynamic Publishing that could lead to arbitrary code execution (RCE) through the min_score modifier of the MTEntries tag (MTC-31415)
  • Fixed an issue in the WXR file import feature that could allow arbitrary files to be written under the site path (MTC-31416)
  • Fixed an issue where invalid SQL could be executed through searches in the Admin screen (MTC-31417)
  • Fixed missing permission checks in the template duplication process (MTC-31418)
  • Fixed missing permission checks in the asset editing and saving processes (MTC-31419)
  • Fixed missing permission checks in the category and folder move processes (MTC-31420)
  • Fixed missing permission checks in the bulk update process for Category Sets (MTC-31421)
  • Fixed missing permission checks in the “Refresh” action on the template listing screen (MTC-31422)
  • Fixed missing permission checks in the folder move process (MTC-31423)
  • Fixed missing permission checks in the asset upload cancellation process (MTC-31424)
  • Fixed missing permission checks in the endpoint for directly inserting assets (MTC-31425)
  • Fixed an issue where the permission check for editing site settings could be bypassed in the generic save process, allowing the Publishing Profile to be changed (MTC-31427)
  • Fixed an issue with the order of permission checks on the rebuild start page (MTC-31429)
  • Fixed an issue in the Data API stats-related endpoints where users without site permissions could access analytics provider access information (MTC-31430)
  • Fixed missing permission checks in the ContentType save process (MTC-31431)
  • Fixed missing permission checks in the save and delete processes for banned IP addresses (BanList) (MTC-31432)
  • Fixed missing permission checks in the Rebuild Trigger save process (MTC-31434)
  • Fixed an issue where the primary category ID of another site could be specified when saving an Entry (MTC-31435)
  • Fixed missing permission checks in the user profile image selection process (MTC-31436)
  • Fixed an issue in site search (mt-search.cgi) where malicious SQL could be executed, potentially exposing data including unpublished data (MTC-31457/CVE-2026-103668)
  • Fixed an issue where an internal redirect could redirect users to a malicious URL when token validation failed and prompted them to sign in again (MTC-31459)
  • Fixed an issue where session invalidation checks for session information retrieved from cookies and other sources were insufficient, potentially allowing users to sign in with an invalidated session ID (MTC-31463)
  • Fixed an issue where CSRF token checks were not performed for various list actions, including duplicating and refreshing templates and unpublishing ContentData (MTC-31495)
  • Fixed an issue in the WXR attachment import feature that could allow file contents to be read (MTC-31510)
  • Fixed a cross-site scripting (XSS) vulnerability on the filter listing screen in the Listing Framework (MTC-31534)
  • Fixed a cross-site scripting (XSS) vulnerability on the asset listing screen (MTC-31535)
  • Fixed a cross-site scripting (XSS) vulnerability in the analytics snippet output (MTStatsSnippet tag) of the Google Analytics 4 plugin (MTC-31536)
  • Fixed a cross-site scripting (XSS) vulnerability in the tag autocomplete feature for Entries and other objects (MTC-31537)
  • Fixed a cross-site scripting (XSS) vulnerability in the asset selection modal of the legacy BlockEditor plugin (MTC-31538)
  • Enhanced validation to prevent control characters and disallowed domain formats from being entered in the “Site URL” and “Archive URL” fields when creating a site or changing site settings (MTC-31540)
  • Fixed a cross-site scripting (XSS) vulnerability on the theme export screen (MTC-31562)
  • Fixed a cross-site scripting (XSS) vulnerability on the rebuild completion pop-up screen (MTC-31563)
  • Fixed a cross-site scripting (XSS) vulnerability in the Listing Framework (MTC-31569)
  • Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 plugin (MTC-31594)
  • Fixed an issue in the upgrade script (mt-upgrade.cgi) that could allow remote code execution (RCE) or malicious SQL execution (MTC-31703/CVE-2026-96408)

Deprecated features

  • Removed the is_cloud template variable from the System Information screen (MTC-31367)

Acknowledgments

We would like to thank everyone for their contributions to this release, especially those who reported these issues and vulnerabilities. We would also like to thank JPCERT/CC and IPA for their assistance in handling the vulnerability information.

And other reports submitted by anonymous:

Checksums

Back