Not a developer? Go to MovableType.com

Documentation

Movable Type 9.0.10 Release Notes

This version of Movable Type was released October 7, 2026.

This release addresses issues found in Movable Type 9.0.8.

New and improved features

  • Added the archive_type column to the mt_deletefileinfo table to improve the accuracy of file deletion when files associated with specific Entries or ContentData are edited or deleted (MTC-28424)
  • Bundled plugins (SendMailByGmail and SendMailByOutlook) that support OAuth 2.0 (Gmail and Outlook) for SMTP authentication in email sending (MTC-31500)
  • Added and updated the bundled CPAN modules in extlib (MTC-31468、MTC-31615)
    • [Added] Authen::SASL (2.2000)
    • [Added] Digest::HMAC (1.05)
    • [Updated] CGI (4.71 → 4.72)
    • [Updated] Crypt::URandom (0.54 → 0.55)
    • [Updated] Digest::Perl::MD5 (1.9 → 1.91)
    • [Updated] HTTP::Date (6.06 → 6.08)
    • [Updated] Image::ExifTool (13.44 → 13.55)
    • [Updated] JSON (4.10 → 4.11)
    • [Updated] JSON::PP (4.16 → 4.18)
    • [Updated] LWP::Protocol::https (6.14 → 6.15)
    • [Updated] MIME::Lite (3.033 → 3.038)
    • [Updated] WWW::RobotRules (6.02 → 6.03)
    • [Updated] TimeDate (2.31 → 2.35)
    • [Updated] URI (5.34 → 5.35)
    • [Updated] libwww-perl (6.81 → 6.83)
    • [Updated] version (0.9933 → 0.9934)

Added and updated plugins

  • Updated the MTBlockEditor plugin to version 1.3.4 (MTC-31616)
  • Updated the AssetUploader plugin to version 1.0.5 (MTC-31627)
  • Updated the MTRichTextEditor plugin to version 1.0.6 (MTC-31628)

MTRichTextEditor plugin

  • Changed the selection color to translucent so that the content remains visible when a table is selected with the mouse (MTC-31288)
  • Added the ability to specify the border style and color, background color, and other table properties (MTC-31289)
  • Allowed multiple CSS file URLs to be specified as a comma-separated list in the Content CSS File setting (MTC-31372)
  • Enabled the button element by default (MTC-31557)
  • Updated Tiptap from version 3.20.1 to 3.27.1 (MTC-31561)

CommonMark plugin

  • Updated the bundled league/commonmark library in the CommonMark plugin from version 2.8.1 to 2.8.2 (MTC-31303)
  • Downgraded the bundled nette/utils library from version 4.1.3 to 4.0.10 to support environments running PHP 8.1 or earlier (MTC-31398)

Dynamic Publishing

  • Added support for PHP 8.5 (MTC-31010)
  • Updated the bundled version of Smarty from 4.5.5 to 4.5.7 (MTC-31542)

Resolved issues

  • Fixed a JavaScript error that occurred when navigating between pages in dialogs, such as the permission assignment and rebuild trigger dialogs (MTC-30587)
  • Fixed an issue where an error message could be displayed on the upgrade screen in environments where DebugMode was set to 1 (MTC-30675)
  • Fixed an issue where the Data Identifier Label setting was reset after repeatedly saving on the ContentType editing screen (MTC-31096)
  • Fixed an issue where the expected warning message was not displayed when viewing a revision containing deleted tags or categories from the revision history of an Entry or Web Page (MTC-31111)
  • Fixed an issue where the contents of unused tag fields were lost when restoring an Entry or Web Page from its revision history (MTC-31117)
  • Fixed an issue where the default value of a custom field was not applied when creating a new folder. Also changed the behavior so that the default value is applied when retrieving a value from an object for which the custom field is not set (MTC-31194)
  • Changed to display a warning message notifying users that the Data Identifier Label setting was cleared when the required setting was disabled for the assigned field or the field was deleted (MTC-31202)
  • Fixed an issue where sites and child sites continued to appear without links in the left menu of the dashboard after a user’s permissions were removed (MTC-31293)
  • Fixed an error that occurred when filtering the Category Set listing screen by the number of categories or ContentTypes (MTC-31295)
  • Fixed an error caused by attempts to retrieve unnecessary columns during initialization in environments where the database schema had changed, such as after an upgrade (MTC-31309)
  • Fixed an issue where an upgrade failed because unnecessary columns from the parent site were retrieved during TrustedHosts checks (MTC-31310)
  • Fixed an issue where pagination did not work correctly in the list for selecting target ContentTypes on the Rebuild Trigger settings screen (MTC-31314)
  • Improved the behavior when removing the required setting from or deleting the field configured as the Data Identifier Label on the ContentType editing screen (MTC-31315)
  • Fixed an issue where the format setting for a Text (Multi-Line) field was not applied in the ContentData preview (MTC-31322)
  • Fixed an issue where files were not transferred during server delivery from a Windows environment to another environment, such as Linux, because relative paths were not replaced correctly due to differences in path separators (MTC-31324)
  • Fixed mt-upgrade.cgi and mt-wizard.cgi to refer to AdminCGIPath instead of CGIPath in PSGI environments (MTC-31326)
  • Fixed an issue where image files were no longer accepted in an asset field of a ContentType, although files such as PDFs could still be uploaded (MTC-31329)
  • Fixed an issue where buttons extended beyond the window and were not visible in the “View Source Code” modal window of MTBlockEditor using TinyMCE 6 (MTC-31333)
  • Fixed an issue where themes placed under the directory specified by the UserThemesDirectory Configuration Directive did not appear on the theme listing screen and could not be applied (MTC-31343)
  • Fixed an error that occurred when rebuilding with the PageBute plugin in Windows environments (MTC-31353)
  • Fixed an issue where the pre_delete_archive_file and post_delete_archive_file callbacks were not called correctly when deleting archive files if the DeleteFilesAfterRebuild Configuration Directive was set to a true value (MTC-31356)
  • Fixed an issue where the Change Note was not displayed in the Status section when selecting the latest revision from the Revision History and navigating to the editing screen (MTC-31371)
  • Fixed a performance issue when sorting the ContentData listing screen by a ContentField such as the Data Identifier Label (MTC-31400)
  • Fixed an issue where categories were not output in the order shown in the Admin screen when using the MTSubCategories tag inside the MTContentField tag (MTC-31469)
  • Fixed an issue where archive files could be unintentionally deleted during ContentData updates because processing was performed with an incorrect combination of category and template mapping (MTC-31522)
  • Fixed an issue where the contents of the first field entered were lost when creating a new Entry or Web Page in rich text format, alternately entering content in the “Body” and “Extended” fields, and then saving (MTC-31595)
  • Fixed an issue where a database error prevented the upgrade from proceeding when a user other than a System administrator was logged in during a version upgrade requiring a schema upgrade (MTC-31598)
  • Changed the conditions under which images from child sites are displayed in the asset list when inserting an image on the Entry editing screen of a parent site or similar screens. Use the RequireAdministerSiteForChildAssets Configuration Directive to restore the previous behavior for backward compatibility (MTC-31517)

AssetUploader

  • Fixed to display an appropriate error message when an image format not supported by the system, such as SVG or AVIF, is selected during asset upload (MTC-31127)
  • Fixed an issue where searches in the image insertion modal matched only filenames and could not search descriptions or labels when AssetUploader was enabled (MTC-31499)
  • Fixed thumbnail preview to keep original aspect ratio at inserting to Image CustomField with AssetUploader, instead of squared on the editing screen (MTC-31512)
  • Fixed an issue where images from child sites appeared as options in the parent site’s asset listing when selecting an image field for a ContentType using AssetUploader (MTC-31513)

MTBlockEditor

  • Fixed an issue where the state of the “Link to original image” checkbox in an Image block was not correctly reflected when saving while using MTBlockEditor with AssetUploader (MTC-31550)
  • Improved MTBlockEditor to use a more generic approach in areas that previously depended on the mt:command attribute (MTC-31614)

MTRichTextEditor

  • Changed MTRichTextEditor to add border="1" and style="border-collapse: collapse" by default when inserting a table from the toolbar (MTC-31332)
  • Fixed an issue where styles from Content CSS files were not applied in the boilerplate insertion modal in MTRichTextEditor (MTC-31166)
  • Fixed an issue where the id and class attributes of table elements could not be edited correctly in the “HTML Structure Editing Mode” of MTRichTextEditor (MTC-31290)
  • Fixed an issue where unnecessary line breaks and spaces were inserted when a ruby tag was used in the HTML editing mode of MTRichTextEditor, then HTML editing mode was reopened and the content was saved (MTC-31497)
  • Fixed an issue where either the text color or background color was reset when both were set and saved in MTRichTextEditor (MTC-31552)
  • Fixed an issue where unnecessary mt-text-block elements were inserted into the editor DOM when saving from HTML editing mode in MTRichTextEditor (MTC-31555)
  • Fixed an issue where the results of using the increase and decrease indent buttons were not preserved correctly, and unnecessary data-mt-indent attributes were added in MTRichTextEditor (MTC-31556)
  • Fixed an issue in the inline mode of MTRichTextEditor, where the top toolbar is hidden, that caused the link editing toolbars to overlap and become unusable (MTC-31558)
  • Adjusted the position and stacking order (z-index) of the contextual toolbar when editing links in MTRichTextEditor, fixing an issue where it was hidden behind the menu bar and became unusable (MTC-31613)
  • Fixed an issue on the “System > Rich Text Editor Settings” screen in the Admin screen where rearranging buttons by drag and drop caused duplicate data to be saved, preventing the screen from being displayed (MTC-31622)
  • Fixed an issue where the layout of the editing area was changed by the Content CSS settings (MTC-31667)
  • Enhanced validation of data retrieved from external sites when embedding Web Pages to allow only the http and https schemes (MTC-31413)
  • Fixed HTML editing mode to prevent entered i, b, strike, and del elements from being automatically converted to other elements (MTC-31698)
  • Fixed an issue in HTML editing mode where a div element entered directly under a dd element was unintentionally removed when saved (MTC-31697)

Movable Type Advanced

  • Fixed an issue in SQL Server where an error occurred when adding a column without a default value during an upgrade (MTC-31532)

Dynamic Publishing

  • Improved SQL query construction in Dynamic Publishing (MTC-31304)
  • Fixed an issue where the “Dynamic Publishing Error” template was not displayed correctly when accessing a nonexistent URL while using Dynamic Publishing, and the browser’s default error page was displayed instead (MTC-31334)
  • Fixed an issue in Dynamic Publishing where an Invalid tag filter error occurred when a tag name contained regular expression special characters such as / (MTC-31380)

Security fixes and improvements

  • Fixed an issue where CSRF token checks were not performed for the “Publish” and “Unpublish” actions on listing screens such as the Entry listing screen (MTC-31366)
  • Fixed a potential OS command injection vulnerability in the run-periodic-tasks script (MTC-31369)
  • Fixed a cross-site scripting (XSS) vulnerability in the restore upload dialog (MTC-31373)
  • Fixed an arbitrary code execution (RCE) vulnerability in the sort_method modifier of the MTSubCategories tag (MTC-31374)
  • Fixed an arbitrary code execution (RCE) vulnerability during restore upload (MTC-31375)
  • Fixed a potential remote code execution (RCE) vulnerability in Dynamic Publishing (MTC-31384)
  • Fixed a cross-site scripting (XSS) vulnerability on the ContentType selection screen (MTC-31385)
  • Fixed a cross-site scripting (XSS) vulnerability on the Rebuild Trigger settings screen (MTC-31386)
  • Fixed a cross-site scripting (XSS) vulnerability on the ContentType Archive Mapping settings screen (MTC-31387)
  • Fixed a cross-site scripting (XSS) vulnerability in the module modifier of the MTInclude tag on the template editing screen (MTC-31383)
  • Fixed a cross-site scripting (XSS) vulnerability in the blog_id modifier of the MTInclude tag on the template editing screen (MTC-31388)
  • Fixed a cross-site scripting (XSS) vulnerability on the ContentData editing and listing screens (MTC-31389)
  • Fixed a cross-site scripting (XSS) vulnerability in the Table field of ContentData (MTC-31390)
  • Fixed a cross-site scripting (XSS) vulnerability in the “Embedded Text” field of ContentData (MTC-31391)
  • Fixed a cross-site scripting (XSS) vulnerability on the template initialization (refresh) screen (MTC-31392)
  • Fixed a cross-site scripting (XSS) vulnerability that occurred when importing specially crafted export data (MTC-31393)
  • Fixed a cross-site scripting (XSS) vulnerability when outputting the MTSearchContentTypes tag in the ContentData search results template (MTC-31394)
  • Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 settings on the Web Services settings screen (MTC-31395)
  • Fixed a cross-site scripting (XSS) vulnerability in the asset selection dialog of the legacy Block Editor (MTC-31396)
  • Fixed a cross-site scripting (XSS) vulnerability in the Image block of the legacy Block Editor (MTC-31397)
  • Fixed a cross-site scripting (XSS) vulnerability in the bulk user import feature and on the LDAP integration settings screen (MTC-31406)
  • Fixed an issue where insufficient CSRF token validation in the Search and Replace feature could cause Entry content to be unintentionally replaced or deleted (MTC-31407)
  • Fixed an issue where insufficient CSRF token checks in the asset information update endpoints allowed item information to be updated unintentionally (MTC-31410)
  • Fixed an issue in Dynamic Publishing that could lead to arbitrary code execution (RCE) through the min_score modifier of the MTEntries tag (MTC-31415)
  • Fixed an issue in the WXR file import feature that could allow arbitrary files to be written under the site path (MTC-31416)
  • Fixed an issue where invalid SQL could be executed through searches in the Admin screen (MTC-31417)
  • Fixed missing permission checks in the template duplication process (MTC-31418)
  • Fixed missing permission checks in the asset editing and saving processes (MTC-31419)
  • Fixed missing permission checks in the category and folder move processes (MTC-31420)
  • Fixed missing permission checks in the bulk update process for Category Sets (MTC-31421)
  • Fixed missing permission checks in the “Refresh” action on the template listing screen (MTC-31422)
  • Fixed missing permission checks in the folder move process (MTC-31423)
  • Fixed missing permission checks in the asset upload cancellation process (MTC-31424)
  • Fixed missing permission checks in the endpoint for directly inserting assets (MTC-31425)
  • Fixed an issue where the permission check for editing site settings could be bypassed in the generic save process, allowing the Publishing Profile to be changed (MTC-31427)
  • Fixed an issue with the order of permission checks on the rebuild start page (MTC-31429)
  • Fixed an issue in the Data API stats-related endpoints where users without site permissions could access analytics provider access information (MTC-31430)
  • Fixed missing permission checks in the ContentType save process (MTC-31431)
  • Fixed missing permission checks in the save and delete processes for banned IP addresses (BanList) (MTC-31432)
  • Fixed an issue where the primary category ID of another site could be specified when saving an Entry (MTC-31435)
  • Fixed missing permission checks in the user profile image selection process (MTC-31436)
  • Fixed an issue in site search (mt-search.cgi) where malicious SQL could be executed, potentially exposing data including unpublished data (MTC-31457/CVE-2026-103668)
  • Fixed an issue where an internal redirect could redirect users to a malicious URL when token validation failed and prompted them to sign in again (MTC-31459)
  • Fixed an issue where session invalidation checks for session information retrieved from cookies and other sources were insufficient, potentially allowing users to sign in with an invalidated session ID (MTC-31463)
  • Fixed an issue where CSRF token checks were not performed for various list actions, including duplicating and refreshing templates and unpublishing ContentData (MTC-31495)
  • Fixed an issue in the WXR attachment import feature that could allow file contents to be read (MTC-31510)
  • Fixed a cross-site scripting (XSS) vulnerability on the filter listing screen in the Listing Framework (MTC-31534)
  • Fixed a cross-site scripting (XSS) vulnerability on the asset listing screen (MTC-31535)
  • Fixed a cross-site scripting (XSS) vulnerability in the analytics snippet output (MTStatsSnippet tag) of the Google Analytics 4 plugin (MTC-31536)
  • Fixed a cross-site scripting (XSS) vulnerability in the tag autocomplete feature for Entries and other objects (MTC-31537)
  • Fixed a cross-site scripting (XSS) vulnerability in the asset selection modal of the legacy BlockEditor plugin (MTC-31538)
  • Enhanced validation to prevent control characters and disallowed domain formats from being entered in the “Site URL” and “Archive URL” fields when creating a site or changing site settings (MTC-31540)
  • Fixed a cross-site scripting (XSS) vulnerability on the theme export screen (MTC-31562)
  • Fixed a cross-site scripting (XSS) vulnerability on the rebuild completion pop-up screen (MTC-31563)
  • Fixed a cross-site scripting (XSS) vulnerability in the Listing Framework (MTC-31569)
  • Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 plugin (MTC-31594)
  • Fixed an issue in the upgrade script (mt-upgrade.cgi) that could allow remote code execution (RCE) or malicious SQL execution (MTC-31703/CVE-2026-96408)

Acknowledgments

We would like to thank everyone for their contributions to this release, especially those who reported these issues and vulnerabilities. We would also like to thank JPCERT/CC and IPA for their assistance in handling the vulnerability information.

And other reports submitted by anonymous:

Checksums

Back