Movable Type 9.0.10 Release Notes
This version of Movable Type was released October 7, 2026.
This release addresses issues found in Movable Type 9.0.8.
New and improved features
- Added the
archive_typecolumn to themt_deletefileinfotable to improve the accuracy of file deletion when files associated with specific Entries or ContentData are edited or deleted (MTC-28424) - Bundled plugins (SendMailByGmail and SendMailByOutlook) that support OAuth 2.0 (Gmail and Outlook) for SMTP authentication in email sending (MTC-31500)
- Added and updated the bundled CPAN modules in
extlib(MTC-31468、MTC-31615)
- [Added]
Authen::SASL(2.2000) - [Added]
Digest::HMAC(1.05) - [Updated]
CGI(4.71 → 4.72) - [Updated]
Crypt::URandom(0.54 → 0.55) - [Updated]
Digest::Perl::MD5(1.9 → 1.91) - [Updated]
HTTP::Date(6.06 → 6.08) - [Updated]
Image::ExifTool(13.44 → 13.55) - [Updated]
JSON(4.10 → 4.11) - [Updated]
JSON::PP(4.16 → 4.18) - [Updated]
LWP::Protocol::https(6.14 → 6.15) - [Updated]
MIME::Lite(3.033 → 3.038) - [Updated]
WWW::RobotRules(6.02 → 6.03) - [Updated]
TimeDate(2.31 → 2.35) - [Updated]
URI(5.34 → 5.35) - [Updated]
libwww-perl(6.81 → 6.83) - [Updated]
version(0.9933 → 0.9934)
- [Added]
Added and updated plugins
- Updated the MTBlockEditor plugin to version 1.3.4 (MTC-31616)
- Updated the AssetUploader plugin to version 1.0.5 (MTC-31627)
- Updated the MTRichTextEditor plugin to version 1.0.6 (MTC-31628)
MTRichTextEditor plugin
- Changed the selection color to translucent so that the content remains visible when a table is selected with the mouse (MTC-31288)
- Added the ability to specify the border style and color, background color, and other table properties (MTC-31289)
- Allowed multiple CSS file URLs to be specified as a comma-separated list in the
Content CSS Filesetting (MTC-31372) - Enabled the
buttonelement by default (MTC-31557) - Updated Tiptap from version 3.20.1 to 3.27.1 (MTC-31561)
CommonMark plugin
- Updated the bundled
league/commonmarklibrary in the CommonMark plugin from version 2.8.1 to 2.8.2 (MTC-31303) - Downgraded the bundled
nette/utilslibrary from version 4.1.3 to 4.0.10 to support environments running PHP 8.1 or earlier (MTC-31398)
Dynamic Publishing
- Added support for PHP 8.5 (MTC-31010)
- Updated the bundled version of Smarty from 4.5.5 to 4.5.7 (MTC-31542)
Resolved issues
- Fixed a JavaScript error that occurred when navigating between pages in dialogs, such as the permission assignment and rebuild trigger dialogs (MTC-30587)
- Fixed an issue where an error message could be displayed on the upgrade screen in environments where
DebugModewas set to1(MTC-30675) - Fixed an issue where the
Data Identifier Labelsetting was reset after repeatedly saving on the ContentType editing screen (MTC-31096) - Fixed an issue where the expected warning message was not displayed when viewing a revision containing deleted tags or categories from the revision history of an Entry or Web Page (MTC-31111)
- Fixed an issue where the contents of unused tag fields were lost when restoring an Entry or Web Page from its revision history (MTC-31117)
- Fixed an issue where the default value of a custom field was not applied when creating a new folder. Also changed the behavior so that the default value is applied when retrieving a value from an object for which the custom field is not set (MTC-31194)
- Changed to display a warning message notifying users that the
Data Identifier Labelsetting was cleared when the required setting was disabled for the assigned field or the field was deleted (MTC-31202) - Fixed an issue where sites and child sites continued to appear without links in the left menu of the dashboard after a user’s permissions were removed (MTC-31293)
- Fixed an error that occurred when filtering the Category Set listing screen by the number of categories or ContentTypes (MTC-31295)
- Fixed an error caused by attempts to retrieve unnecessary columns during initialization in environments where the database schema had changed, such as after an upgrade (MTC-31309)
- Fixed an issue where an upgrade failed because unnecessary columns from the parent site were retrieved during
TrustedHostschecks (MTC-31310) - Fixed an issue where pagination did not work correctly in the list for selecting target ContentTypes on the Rebuild Trigger settings screen (MTC-31314)
- Improved the behavior when removing the required setting from or deleting the field configured as the
Data Identifier Labelon the ContentType editing screen (MTC-31315) - Fixed an issue where the format setting for a
Text (Multi-Line)field was not applied in the ContentData preview (MTC-31322) - Fixed an issue where files were not transferred during server delivery from a Windows environment to another environment, such as Linux, because relative paths were not replaced correctly due to differences in path separators (MTC-31324)
- Fixed
mt-upgrade.cgiandmt-wizard.cgito refer toAdminCGIPathinstead ofCGIPathin PSGI environments (MTC-31326) - Fixed an issue where image files were no longer accepted in an asset field of a ContentType, although files such as PDFs could still be uploaded (MTC-31329)
- Fixed an issue where buttons extended beyond the window and were not visible in the “View Source Code” modal window of MTBlockEditor using TinyMCE 6 (MTC-31333)
- Fixed an issue where themes placed under the directory specified by the
UserThemesDirectoryConfiguration Directive did not appear on the theme listing screen and could not be applied (MTC-31343) - Fixed an error that occurred when rebuilding with the PageBute plugin in Windows environments (MTC-31353)
- Fixed an issue where the
pre_delete_archive_fileandpost_delete_archive_filecallbacks were not called correctly when deleting archive files if theDeleteFilesAfterRebuildConfiguration Directive was set to a true value (MTC-31356) - Fixed an issue where the Change Note was not displayed in the Status section when selecting the latest revision from the Revision History and navigating to the editing screen (MTC-31371)
- Fixed a performance issue when sorting the ContentData listing screen by a ContentField such as the
Data Identifier Label(MTC-31400) - Fixed an issue where categories were not output in the order shown in the Admin screen when using the
MTSubCategoriestag inside theMTContentFieldtag (MTC-31469) - Fixed an issue where archive files could be unintentionally deleted during ContentData updates because processing was performed with an incorrect combination of category and template mapping (MTC-31522)
- Fixed an issue where the contents of the first field entered were lost when creating a new Entry or Web Page in rich text format, alternately entering content in the “Body” and “Extended” fields, and then saving (MTC-31595)
- Fixed an issue where a database error prevented the upgrade from proceeding when a user other than a System administrator was logged in during a version upgrade requiring a schema upgrade (MTC-31598)
- Changed the conditions under which images from child sites are displayed in the asset list when inserting an image on the Entry editing screen of a parent site or similar screens. Use the
RequireAdministerSiteForChildAssetsConfiguration Directive to restore the previous behavior for backward compatibility (MTC-31517)
AssetUploader
- Fixed to display an appropriate error message when an image format not supported by the system, such as SVG or AVIF, is selected during asset upload (MTC-31127)
- Fixed an issue where searches in the image insertion modal matched only filenames and could not search descriptions or labels when AssetUploader was enabled (MTC-31499)
- Fixed thumbnail preview to keep original aspect ratio at inserting to Image CustomField with AssetUploader, instead of squared on the editing screen (MTC-31512)
- Fixed an issue where images from child sites appeared as options in the parent site’s asset listing when selecting an image field for a ContentType using AssetUploader (MTC-31513)
MTBlockEditor
- Fixed an issue where the state of the “Link to original image” checkbox in an Image block was not correctly reflected when saving while using MTBlockEditor with AssetUploader (MTC-31550)
- Improved MTBlockEditor to use a more generic approach in areas that previously depended on the
mt:commandattribute (MTC-31614)
MTRichTextEditor
- Changed MTRichTextEditor to add
border="1"andstyle="border-collapse: collapse"by default when inserting a table from the toolbar (MTC-31332) - Fixed an issue where styles from Content CSS files were not applied in the boilerplate insertion modal in MTRichTextEditor (MTC-31166)
- Fixed an issue where the
idandclassattributes oftableelements could not be edited correctly in the “HTML Structure Editing Mode” of MTRichTextEditor (MTC-31290) - Fixed an issue where unnecessary line breaks and spaces were inserted when a
rubytag was used in the HTML editing mode of MTRichTextEditor, then HTML editing mode was reopened and the content was saved (MTC-31497) - Fixed an issue where either the text color or background color was reset when both were set and saved in MTRichTextEditor (MTC-31552)
- Fixed an issue where unnecessary
mt-text-blockelements were inserted into the editor DOM when saving from HTML editing mode in MTRichTextEditor (MTC-31555) - Fixed an issue where the results of using the increase and decrease indent buttons were not preserved correctly, and unnecessary
data-mt-indentattributes were added in MTRichTextEditor (MTC-31556) - Fixed an issue in the inline mode of MTRichTextEditor, where the top toolbar is hidden, that caused the link editing toolbars to overlap and become unusable (MTC-31558)
- Adjusted the position and stacking order (
z-index) of the contextual toolbar when editing links in MTRichTextEditor, fixing an issue where it was hidden behind the menu bar and became unusable (MTC-31613) - Fixed an issue on the “System > Rich Text Editor Settings” screen in the Admin screen where rearranging buttons by drag and drop caused duplicate data to be saved, preventing the screen from being displayed (MTC-31622)
- Fixed an issue where the layout of the editing area was changed by the Content CSS settings (MTC-31667)
- Enhanced validation of data retrieved from external sites when embedding Web Pages to allow only the
httpandhttpsschemes (MTC-31413) - Fixed HTML editing mode to prevent entered
i,b,strike, anddelelements from being automatically converted to other elements (MTC-31698) - Fixed an issue in HTML editing mode where a
divelement entered directly under addelement was unintentionally removed when saved (MTC-31697)
Movable Type Advanced
- Fixed an issue in SQL Server where an error occurred when adding a column without a default value during an upgrade (MTC-31532)
Dynamic Publishing
- Improved SQL query construction in Dynamic Publishing (MTC-31304)
- Fixed an issue where the “Dynamic Publishing Error” template was not displayed correctly when accessing a nonexistent URL while using Dynamic Publishing, and the browser’s default error page was displayed instead (MTC-31334)
- Fixed an issue in Dynamic Publishing where an
Invalid tag filtererror occurred when a tag name contained regular expression special characters such as/(MTC-31380)
Security fixes and improvements
- Fixed an issue where CSRF token checks were not performed for the “Publish” and “Unpublish” actions on listing screens such as the Entry listing screen (MTC-31366)
- Fixed a potential OS command injection vulnerability in the
run-periodic-tasksscript (MTC-31369) - Fixed a cross-site scripting (XSS) vulnerability in the restore upload dialog (MTC-31373)
- Fixed an arbitrary code execution (RCE) vulnerability in the
sort_methodmodifier of theMTSubCategoriestag (MTC-31374) - Fixed an arbitrary code execution (RCE) vulnerability during restore upload (MTC-31375)
- Fixed a potential remote code execution (RCE) vulnerability in Dynamic Publishing (MTC-31384)
- Fixed a cross-site scripting (XSS) vulnerability on the ContentType selection screen (MTC-31385)
- Fixed a cross-site scripting (XSS) vulnerability on the Rebuild Trigger settings screen (MTC-31386)
- Fixed a cross-site scripting (XSS) vulnerability on the ContentType Archive Mapping settings screen (MTC-31387)
- Fixed a cross-site scripting (XSS) vulnerability in the
modulemodifier of theMTIncludetag on the template editing screen (MTC-31383) - Fixed a cross-site scripting (XSS) vulnerability in the
blog_idmodifier of theMTIncludetag on the template editing screen (MTC-31388) - Fixed a cross-site scripting (XSS) vulnerability on the ContentData editing and listing screens (MTC-31389)
- Fixed a cross-site scripting (XSS) vulnerability in the Table field of ContentData (MTC-31390)
- Fixed a cross-site scripting (XSS) vulnerability in the “Embedded Text” field of ContentData (MTC-31391)
- Fixed a cross-site scripting (XSS) vulnerability on the template initialization (refresh) screen (MTC-31392)
- Fixed a cross-site scripting (XSS) vulnerability that occurred when importing specially crafted export data (MTC-31393)
- Fixed a cross-site scripting (XSS) vulnerability when outputting the
MTSearchContentTypestag in the ContentData search results template (MTC-31394) - Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 settings on the Web Services settings screen (MTC-31395)
- Fixed a cross-site scripting (XSS) vulnerability in the asset selection dialog of the legacy Block Editor (MTC-31396)
- Fixed a cross-site scripting (XSS) vulnerability in the Image block of the legacy Block Editor (MTC-31397)
- Fixed a cross-site scripting (XSS) vulnerability in the bulk user import feature and on the LDAP integration settings screen (MTC-31406)
- Fixed an issue where insufficient CSRF token validation in the Search and Replace feature could cause Entry content to be unintentionally replaced or deleted (MTC-31407)
- Fixed an issue where insufficient CSRF token checks in the asset information update endpoints allowed item information to be updated unintentionally (MTC-31410)
- Fixed an issue in Dynamic Publishing that could lead to arbitrary code execution (RCE) through the
min_scoremodifier of theMTEntriestag (MTC-31415) - Fixed an issue in the WXR file import feature that could allow arbitrary files to be written under the site path (MTC-31416)
- Fixed an issue where invalid SQL could be executed through searches in the Admin screen (MTC-31417)
- Fixed missing permission checks in the template duplication process (MTC-31418)
- Fixed missing permission checks in the asset editing and saving processes (MTC-31419)
- Fixed missing permission checks in the category and folder move processes (MTC-31420)
- Fixed missing permission checks in the bulk update process for Category Sets (MTC-31421)
- Fixed missing permission checks in the “Refresh” action on the template listing screen (MTC-31422)
- Fixed missing permission checks in the folder move process (MTC-31423)
- Fixed missing permission checks in the asset upload cancellation process (MTC-31424)
- Fixed missing permission checks in the endpoint for directly inserting assets (MTC-31425)
- Fixed an issue where the permission check for editing site settings could be bypassed in the generic save process, allowing the Publishing Profile to be changed (MTC-31427)
- Fixed an issue with the order of permission checks on the rebuild start page (MTC-31429)
- Fixed an issue in the Data API stats-related endpoints where users without site permissions could access analytics provider access information (MTC-31430)
- Fixed missing permission checks in the ContentType save process (MTC-31431)
- Fixed missing permission checks in the save and delete processes for banned IP addresses (
BanList) (MTC-31432) - Fixed an issue where the primary category ID of another site could be specified when saving an Entry (MTC-31435)
- Fixed missing permission checks in the user profile image selection process (MTC-31436)
- Fixed an issue in site search (
mt-search.cgi) where malicious SQL could be executed, potentially exposing data including unpublished data (MTC-31457/CVE-2026-103668) - Fixed an issue where an internal redirect could redirect users to a malicious URL when token validation failed and prompted them to sign in again (MTC-31459)
- Fixed an issue where session invalidation checks for session information retrieved from cookies and other sources were insufficient, potentially allowing users to sign in with an invalidated session ID (MTC-31463)
- Fixed an issue where CSRF token checks were not performed for various list actions, including duplicating and refreshing templates and unpublishing ContentData (MTC-31495)
- Fixed an issue in the WXR attachment import feature that could allow file contents to be read (MTC-31510)
- Fixed a cross-site scripting (XSS) vulnerability on the filter listing screen in the Listing Framework (MTC-31534)
- Fixed a cross-site scripting (XSS) vulnerability on the asset listing screen (MTC-31535)
- Fixed a cross-site scripting (XSS) vulnerability in the analytics snippet output (
MTStatsSnippettag) of the Google Analytics 4 plugin (MTC-31536) - Fixed a cross-site scripting (XSS) vulnerability in the tag autocomplete feature for Entries and other objects (MTC-31537)
- Fixed a cross-site scripting (XSS) vulnerability in the asset selection modal of the legacy BlockEditor plugin (MTC-31538)
- Enhanced validation to prevent control characters and disallowed domain formats from being entered in the “Site URL” and “Archive URL” fields when creating a site or changing site settings (MTC-31540)
- Fixed a cross-site scripting (XSS) vulnerability on the theme export screen (MTC-31562)
- Fixed a cross-site scripting (XSS) vulnerability on the rebuild completion pop-up screen (MTC-31563)
- Fixed a cross-site scripting (XSS) vulnerability in the Listing Framework (MTC-31569)
- Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 plugin (MTC-31594)
- Fixed an issue in the upgrade script (
mt-upgrade.cgi) that could allow remote code execution (RCE) or malicious SQL execution (MTC-31703/CVE-2026-96408)
Acknowledgments
We would like to thank everyone for their contributions to this release, especially those who reported these issues and vulnerabilities. We would also like to thank JPCERT/CC and IPA for their assistance in handling the vulnerability information.
- RyotaK, GMO Flatt Security Inc. (MTC-31457/CVE-2026-103668, MTC-31703/CVE-2026-96408)
- Shintaro Kuboki, KANSE Co., Ltd. (MTC-31096, MTC-31202/FEEDBACK-2667)
- Yujiro Araki (MTC-31117/FEEDBACK-2646)
- Seiji Hamagaki (MTC-31497/FEEDBACK-2665)
- Homare Urayama (MTC-31499/FEEDBACK-2666)
- Hatsuru Maegoya, COLSIS, Inc. (MTC-31343/FEEDBACK-2661)
And other reports submitted by anonymous:
- (MTC-31096/FEEDBACK-2657)
- (MTC-31166/FEEDBACK-2651)
- (MTC-31194/FEEDBACK-2655)
- (MTC-31202/FEEDBACK-2657)
- (MTC-31322/FEEDBACK-2658)