Movable Type 8.8.6 Release Notes
This version of Movable Type was released October 7, 2026.
This release addresses issues found in Movable Type 8.8.5.
New and improved features
- Added the
archive_typecolumn to themt_deletefileinfotable to improve the accuracy of file deletion when files associated with specific Entries or ContentData are edited or deleted (MTC-28424) - Added the Configuration Directive
UseCodeMirror6. Setting it to1uses CodeMirror 6 as the code editor on the template editing screen. The default value is0, which uses CodeMirror 5 (MTC-30846) - Added the Configuration Directive
MailSMTPOAuthProvider, which specifies the authentication provider to use with OAuth 2.0 for SMTP authentication (MTC-31492) - Disabled the License Verification plugin and replaced it with the License Pack add-on (MTC-30730)
- Added the option to display the log “Level” as a column through Display Options on the System Log listing screen in the Admin screen (MTC-31503)
- Added and updated the bundled CPAN modules in
extlib(MTC-31615)
- [Updated]
CGI(4.71 → 4.72) - [Updated]
Crypt::URandom(0.54 → 0.55) - [Updated]
Digest::Perl::MD5(1.9 → 1.91) - [Updated]
HTTP::Daemon(6.16 → 6.17) - [Updated]
HTTP::Date(6.06 → 6.08) - [Updated]
Image::ExifTool(13.44 → 13.55) - [Updated]
JSON(4.10 → 4.11) - [Updated]
JSON::PP(4.16 → 4.18) - [Updated]
LWP::Protocol::https(6.14 → 6.15) - [Updated]
MIME::Lite(3.033 → 3.038) - [Updated]
WWW::RobotRules(6.02 → 6.03) - [Updated]
TimeDate(2.31 → 2.35) - [Updated]
URI(5.34 → 5.35) - [Updated]
libwww-perl(6.81 → 6.83) - [Updated]
version(0.9933 → 0.9934)
- [Updated]
Added and updated plugins
- Updated the MFA-TOTP plugin to version 1.2.1 (MTC-31588)
- Updated the MTBlockEditor plugin to version 1.4.0 (MTC-31617)
- Updated the MTRichTextEditor plugin to version 1.0.6 (MTC-31628)
MFA TOTP plugin
- Added the
autocomplete="one-time-code"attribute to the verification code input field in the MFA-TOTP plugin to improve the autofill experience with password managers and other tools (MTC-31360)
MTRichTextEditor plugin
- Changed the selection color to translucent so that the content remains visible when a table is selected with the mouse (MTC-31288)
- Added the ability to specify the border style and color, background color, and other table properties (MTC-31289)
- Allowed multiple CSS file URLs to be specified as a comma-separated list in the
Content CSS Filesetting (MTC-31372) - Enabled the
buttonelement by default (MTC-31557) - Updated Tiptap from version 3.20.1 to 3.27.1 (MTC-31561)
Dynamic Publishing
- Added support for PHP 8.5 (MTC-31010)
- Updated the bundled version of Smarty from 4.5.5 to 4.5.7 (MTC-31542)
Resolved issues
- Fixed the
Use of uninitialized valuewarning that occurred when theSiteURLConfiguration Directive was undefined (CLOUD-581) - Fixed a JavaScript error that occurred when navigating between pages in dialogs, such as the permission assignment and rebuild trigger dialogs (MTC-30587)
- Fixed an issue where the
Data Identifier Labelsetting was reset after repeatedly saving on the ContentType editing screen (MTC-31096) - Fixed an issue where the expected warning message was not displayed when viewing a revision containing deleted tags or categories from the revision history of an Entry or Web Page (MTC-31111)
- Fixed an issue where the contents of unused tag fields were lost when restoring an Entry or Web Page from its revision history (MTC-31117)
- Changed to display a warning message notifying users that the
Data Identifier Labelsetting was cleared when the required setting was disabled for the assigned field or the field was deleted (MTC-31202) - Fixed an issue where sites and child sites continued to appear without links in the left menu of the dashboard after a user’s permissions were removed (MTC-31293)
- Fixed an error that occurred when filtering the Category Set listing screen by the number of categories or ContentTypes (MTC-31295)
- Fixed an issue where pagination did not work correctly in the list for selecting target ContentTypes on the Rebuild Trigger settings screen (MTC-31314)
- Improved the behavior when removing the required setting from or deleting the field configured as the
Data Identifier Labelon the ContentType editing screen (MTC-31315) - Fixed an issue where the format setting for a
Text (Multi-Line)field was not applied in the ContentData preview (MTC-31322) - Fixed an issue where files were not transferred during server delivery from a Windows environment to another environment, such as Linux, because relative paths were not replaced correctly due to differences in path separators (MTC-31324)
- Fixed
mt-upgrade.cgiandmt-wizard.cgito refer toAdminCGIPathinstead ofCGIPathin PSGI environments (MTC-31326) - Fixed an issue where buttons extended beyond the window and were not visible in the “View Source Code” modal window of MTBlockEditor using TinyMCE 6 (MTC-31333)
- Fixed the
Use of uninitialized valuewarning that occurred when sorting a blog list, such as on the System Log listing screen, when the blog ID was undefined (MTC-31340) - Fixed an issue where themes placed under the directory specified by the
UserThemesDirectoryConfiguration Directive did not appear on the theme listing screen and could not be applied (MTC-31343) - Fixed an issue where the
pre_delete_archive_fileandpost_delete_archive_filecallbacks were not called correctly when deleting archive files if theDeleteFilesAfterRebuildConfiguration Directive was set to a true value (MTC-31356) - Fixed a performance issue when sorting the ContentData listing screen by a ContentField such as the
Data Identifier Label(MTC-31400) - Fixed an issue where categories were not output in the order shown in the Admin screen when using the
MTSubCategoriestag inside theMTContentFieldtag (MTC-31469) - Fixed an issue in Movable Type 8.8.x where the “Set up access statistics” link in Site Settings was hidden (MTC-31502)
- Fixed an issue in PSGI environments where the values of filter fields (select boxes) in the Admin screen were cached in the language used during the initial access, preventing the display language from switching correctly (MTC-31507)
- Fixed an issue where the process of adding missing default templates during an upgrade generated an excessively large SQL query, which could cause an error in SQL Server (MTC-31520)
- Fixed an issue where archive files could be unintentionally deleted during ContentData updates because processing was performed with an incorrect combination of category and template mapping (MTC-31522)
- Fixed an issue where the contents of the first field entered were lost when creating a new Entry or Web Page in rich text format, alternately entering content in the “Body” and “Extended” fields, and then saving (MTC-31595)
- Fixed an issue where a database error prevented the upgrade from proceeding when a user other than a System administrator was logged in during a version upgrade requiring a schema upgrade (MTC-31598)
- Changed the conditions under which images from child sites are displayed in the asset list when inserting an image on the Entry editing screen of a parent site or similar screens. Use the
RequireAdministerSiteForChildAssetsConfiguration Directive to restore the previous behavior for backward compatibility (MTC-31517)
MTBlockEditor
- Improved MTBlockEditor to use a more generic approach in areas that previously depended on the
mt:commandattribute (MTC-31614)
MTRichTextEditor
- Changed MTRichTextEditor to add
border="1"andstyle="border-collapse: collapse"by default when inserting a table from the toolbar (MTC-31332) - Fixed an issue where styles from Content CSS files were not applied in the boilerplate insertion modal in MTRichTextEditor (MTC-31166)
- Fixed an issue where the
idandclassattributes oftableelements could not be edited correctly in the “HTML Structure Editing Mode” of MTRichTextEditor (MTC-31290) - Fixed an issue where unnecessary line breaks and spaces were inserted when a
rubytag was used in the HTML editing mode of MTRichTextEditor, then HTML editing mode was reopened and the content was saved (MTC-31497) - Fixed an issue where either the text color or background color was reset when both were set and saved in MTRichTextEditor (MTC-31552)
- Fixed an issue where unnecessary
mt-text-blockelements were inserted into the editor DOM when saving from HTML editing mode in MTRichTextEditor (MTC-31555) - Fixed an issue where the results of using the increase and decrease indent buttons were not preserved correctly, and unnecessary
data-mt-indentattributes were added in MTRichTextEditor (MTC-31556) - Fixed an issue in the inline mode of MTRichTextEditor, where the top toolbar is hidden, that caused the link editing toolbars to overlap and become unusable (MTC-31558)
- Adjusted the position and stacking order (
z-index) of the contextual toolbar when editing links in MTRichTextEditor, fixing an issue where it was hidden behind the menu bar and became unusable (MTC-31613) - Fixed an issue on the “System > Rich Text Editor Settings” screen in the Admin screen where rearranging buttons by drag and drop caused duplicate data to be saved, preventing the screen from being displayed (MTC-31622)
- Fixed an issue where the layout of the editing area was changed by the Content CSS settings (MTC-31667)
- Enhanced validation of data retrieved from external sites when embedding Web Pages to allow only the
httpandhttpsschemes (MTC-31413) - Fixed HTML editing mode to prevent entered
i,b,strike, anddelelements from being automatically converted to other elements (MTC-31698) - Fixed an issue in HTML editing mode where a
divelement entered directly under addelement was unintentionally removed when saved (MTC-31697)
Movable Type Advanced
- Fixed an issue in SQL Server where an error occurred when adding a column without a default value during an upgrade (MTC-31532)
Dynamic Publishing
- Improved SQL query construction in Dynamic Publishing (MTC-31304)
- Fixed an issue where the “Dynamic Publishing Error” template was not displayed correctly when accessing a nonexistent URL while using Dynamic Publishing, and the browser’s default error page was displayed instead (MTC-31334)
- Fixed an issue in Dynamic Publishing where an
Invalid tag filtererror occurred when a tag name contained regular expression special characters such as/(MTC-31380)
Security fixes and improvements
- Fixed an issue where CSRF token checks were not performed for the “Publish” and “Unpublish” actions on listing screens such as the Entry listing screen (MTC-31366)
- Fixed a potential OS command injection vulnerability in the
run-periodic-tasksscript (MTC-31369) - Fixed a cross-site scripting (XSS) vulnerability in the restore upload dialog (MTC-31373)
- Fixed an arbitrary code execution (RCE) vulnerability in the
sort_methodmodifier of theMTSubCategoriestag (MTC-31374) - Fixed an arbitrary code execution (RCE) vulnerability during restore upload (MTC-31375)
- Fixed a potential remote code execution (RCE) vulnerability in Dynamic Publishing (MTC-31384)
- Fixed a cross-site scripting (XSS) vulnerability on the ContentType selection screen (MTC-31385)
- Fixed a cross-site scripting (XSS) vulnerability on the Rebuild Trigger settings screen (MTC-31386)
- Fixed a cross-site scripting (XSS) vulnerability on the ContentType Archive Mapping settings screen (MTC-31387)
- Fixed a cross-site scripting (XSS) vulnerability in the
modulemodifier of theMTIncludetag on the template editing screen (MTC-31383) - Fixed a cross-site scripting (XSS) vulnerability in the
blog_idmodifier of theMTIncludetag on the template editing screen (MTC-31388) - Fixed a cross-site scripting (XSS) vulnerability on the ContentData editing and listing screens (MTC-31389)
- Fixed a cross-site scripting (XSS) vulnerability in the Table field of ContentData (MTC-31390)
- Fixed a cross-site scripting (XSS) vulnerability in the “Embedded Text” field of ContentData (MTC-31391)
- Fixed a cross-site scripting (XSS) vulnerability on the template initialization (refresh) screen (MTC-31392)
- Fixed a cross-site scripting (XSS) vulnerability that occurred when importing specially crafted export data (MTC-31393)
- Fixed a cross-site scripting (XSS) vulnerability when outputting the
MTSearchContentTypestag in the ContentData search results template (MTC-31394) - Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 settings on the Web Services settings screen (MTC-31395)
- Fixed a cross-site scripting (XSS) vulnerability in the asset selection dialog of the legacy Block Editor (MTC-31396)
- Fixed a cross-site scripting (XSS) vulnerability in the Image block of the legacy Block Editor (MTC-31397)
- Fixed a cross-site scripting (XSS) vulnerability on the “Basic Authentication Management” screen in the Cloud Edition (MTC-31401)
- Fixed a cross-site scripting (XSS) vulnerability on the “Domain Settings” screen in the Cloud Edition (MTC-31402)
- Fixed a cross-site scripting (XSS) vulnerability on the “Web Server Settings” screen in the Cloud Edition (MTC-31403)
- Fixed a cross-site scripting (XSS) vulnerability on the “Access Restriction Settings” screen in the Cloud Edition (MTC-31404)
- Fixed a cross-site scripting (XSS) vulnerability in the system security settings of the Cloud Edition (MTC-31405)
- Fixed a cross-site scripting (XSS) vulnerability in the bulk user import feature and on the LDAP integration settings screen (MTC-31406)
- Fixed an issue where insufficient CSRF token validation in the Search and Replace feature could cause Entry content to be unintentionally replaced or deleted (MTC-31407)
- Fixed an issue where insufficient CSRF token checks in the asset information update endpoints allowed item information to be updated unintentionally (MTC-31410)
- Fixed an issue in the redirect settings of the Cloud Edition where processing continued even when CSRF token validation failed (MTC-31411)
- Fixed an issue in the web server settings of the Cloud Edition where processing continued even when CSRF token validation failed (MTC-31412)
- Fixed an issue in Dynamic Publishing that could lead to arbitrary code execution (RCE) through the
min_scoremodifier of theMTEntriestag (MTC-31415) - Fixed an issue in the WXR file import feature that could allow arbitrary files to be written under the site path (MTC-31416)
- Fixed an issue where invalid SQL could be executed through searches in the Admin screen (MTC-31417)
- Fixed missing permission checks in the template duplication process (MTC-31418)
- Fixed missing permission checks in the asset editing and saving processes (MTC-31419)
- Fixed missing permission checks in the category and folder move processes (MTC-31420)
- Fixed missing permission checks in the bulk update process for Category Sets (MTC-31421)
- Fixed missing permission checks in the “Refresh” action on the template listing screen (MTC-31422)
- Fixed missing permission checks in the folder move process (MTC-31423)
- Fixed missing permission checks in the asset upload cancellation process (MTC-31424)
- Fixed missing permission checks in the endpoint for directly inserting assets (MTC-31425)
- Fixed an issue where the permission check for editing site settings could be bypassed in the generic save process, allowing the Publishing Profile to be changed (MTC-31427)
- Fixed an issue with the order of permission checks on the rebuild start page (MTC-31429)
- Fixed an issue in the Data API stats-related endpoints where users without site permissions could access analytics provider access information (MTC-31430)
- Fixed missing permission checks in the ContentType save process (MTC-31431)
- Fixed missing permission checks in the save and delete processes for banned IP addresses (
BanList) (MTC-31432) - Fixed missing permission checks in the Rebuild Trigger save process (MTC-31434)
- Fixed an issue where the primary category ID of another site could be specified when saving an Entry (MTC-31435)
- Fixed missing permission checks in the user profile image selection process (MTC-31436)
- Fixed an issue in site search (
mt-search.cgi) where malicious SQL could be executed, potentially exposing data including unpublished data (MTC-31457/CVE-2026-103668) - Fixed an issue where an internal redirect could redirect users to a malicious URL when token validation failed and prompted them to sign in again (MTC-31459)
- Fixed an issue where session invalidation checks for session information retrieved from cookies and other sources were insufficient, potentially allowing users to sign in with an invalidated session ID (MTC-31463)
- Fixed an issue where CSRF token checks were not performed for various list actions, including duplicating and refreshing templates and unpublishing ContentData (MTC-31495)
- Fixed an issue in the WXR attachment import feature that could allow file contents to be read (MTC-31510)
- Fixed a cross-site scripting (XSS) vulnerability on the filter listing screen in the Listing Framework (MTC-31534)
- Fixed a cross-site scripting (XSS) vulnerability on the asset listing screen (MTC-31535)
- Fixed a cross-site scripting (XSS) vulnerability in the analytics snippet output (
MTStatsSnippettag) of the Google Analytics 4 plugin (MTC-31536) - Fixed a cross-site scripting (XSS) vulnerability in the tag autocomplete feature for Entries and other objects (MTC-31537)
- Fixed a cross-site scripting (XSS) vulnerability in the asset selection modal of the legacy BlockEditor plugin (MTC-31538)
- Enhanced validation to prevent control characters and disallowed domain formats from being entered in the “Site URL” and “Archive URL” fields when creating a site or changing site settings (MTC-31540)
- Fixed a cross-site scripting (XSS) vulnerability on the theme export screen (MTC-31562)
- Fixed a cross-site scripting (XSS) vulnerability on the rebuild completion pop-up screen (MTC-31563)
- Fixed a cross-site scripting (XSS) vulnerability in the Listing Framework (MTC-31569)
- Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 plugin (MTC-31594)
- Fixed an issue in the upgrade script (
mt-upgrade.cgi) that could allow remote code execution (RCE) or malicious SQL execution (MTC-31703/CVE-2026-96408)
Deprecated features
- Removed the
is_cloudtemplate variable from the System Information screen (MTC-31367)
Acknowledgments
We would like to thank everyone for their contributions to this release, especially those who reported these issues and vulnerabilities. We would also like to thank JPCERT/CC and IPA for their assistance in handling the vulnerability information.
- RyotaK, GMO Flatt Security Inc. (MTC-31457/CVE-2026-103668, MTC-31703/CVE-2026-96408)
- Shintaro Kuboki, KANSE Co., Ltd. (MTC-31096/FEEDBACK-2667, MTC-31202/FEEDBACK-2667)
- Yujiro Araki (MTC-31117/FEEDBACK-2646)
- Hatsuru Maegoya, COLSIS, Inc. (MTC-31343/FEEDBACK-2661)
- Seiji Hamagaki (MTC-31497/FEEDBACK-2665)
And other reports submitted by anonymous:
- (MTC-31096/FEEDBACK-2657)
- (MTC-31166/FEEDBACK-2651)
- (MTC-31202/FEEDBACK-2657)
- (MTC-31322/FEEDBACK-2658)