Movable Type 9.3.0 Release Notes
This version of Movable Type was released October 7, 2026.
This release of Movable Type includes feature improvements, bug fixes, and other changes. This version also includes fixes and improvements for multiple security issues.
New and improved features
- Added the ability to validate selected ContentData from the ContentData listing screen (MTC-31185)
- Added the ability to duplicate Entries and Web Pages (CopyThisEntry plugin version 1.16) (MTC-31306)
- Added the ability to duplicate Entries, Web Pages, and ContentData from their respective listing screens (MTC-29767)
- Added the ability to add and edit “Change Notes” in the revision history of Entries, Web Pages, ContentData, and templates (MTC-31313)
- Disabled the License Verification plugin and replaced it with the License Pack add-on (MTC-30730)
- Added the option to display the log “Level” as a column through Display Options on the System Log listing screen in the Admin screen (MTC-31503)
- Added the
archive_typecolumn to themt_deletefileinfotable to improve the accuracy of file deletion when files associated with specific Entries or ContentData are edited or deleted (MTC-28424) - Improved Admin screen templates by progressively replacing attribute names beginning with
mt:that do not conform to the HTML specification with HTML validation-compliant attribute names beginning withdata-mt-(MTC-31570) - Added the Configuration Directive
UseCodeMirror6. Setting it to1uses CodeMirror 6 as the code editor on the template editing screen. The default value is0, which uses CodeMirror 5 (MTC-30846) - Added the Configuration Directive
MailSMTPOAuthProvider, which specifies the authentication provider to use with OAuth 2.0 for SMTP authentication (MTC-31492) - Changed to log a warning about the future deprecation of
SafeModewhen the Configuration Directive is disabled in the software edition (MTC-31092) - Added and updated the bundled CPAN modules in
extlib(MTC-31462、MTC-31615)
- [Added]
Authen::SASL(2.2000) - [Added]
Digest::HMAC(1.05) - [Updated]
CGI(4.71 → 4.72) - [Updated]
Crypt::URandom(0.54 → 0.55) - [Updated]
Digest::Perl::MD5(1.9 → 1.91) - [Updated]
HTTP::Date(6.06 → 6.08) - [Updated]
Image::ExifTool(13.44 → 13.55) - [Updated]
JSON(4.10 → 4.11) - [Updated]
JSON::PP(4.16 → 4.18) - [Updated]
LWP::Protocol::https(6.14 → 6.15) - [Updated]
MIME::Lite(3.035 → 3.038) - [Updated]
TimeDate(2.31 → 2.35) - [Updated]
URI(5.34 → 5.35) - [Updated]
WWW::RobotRules(6.02 → 6.03) - [Updated]
libwww-perl(6.81 → 6.83) - [Updated]
version(0.9933 → 0.9934)
- [Added]
Added and updated plugins
- Added version 1.16 of the CopyThisEntry plugin (MTC-31306)
- Updated the MFA-TOTP plugin to version 1.2.1 (MTC-31588)
- Updated the MTBlockEditor plugin to version 1.4.0 (MTC-31617)
- Updated the AssetUploader plugin to version 1.0.5 (MTC-31627)
- Updated the MTRichTextEditor plugin to version 1.0.6 (MTC-31628)
MFA TOTP plugin
- Added the
autocomplete="one-time-code"attribute to the verification code input field in the MFA-TOTP plugin to improve the autofill experience with password managers and other tools (MTC-31360)
MTRichTextEditor plugin
- Changed the selection color to translucent so that the content remains visible when a table is selected with the mouse (MTC-31288)
- Added the ability to specify the border style and color, background color, and other table properties (MTC-31289)
- Allowed multiple CSS file URLs to be specified as a comma-separated list in the
Content CSS Filesetting (MTC-31372) - Enabled the
buttonelement by default (MTC-31557) - Updated Tiptap from version 3.20.1 to 3.27.1 (MTC-31561)
CommonMark plugin
- Updated the bundled
league/commonmarklibrary in the CommonMark plugin from version 2.8.1 to 2.8.2 (MTC-31303) - Downgraded the bundled
nette/utilslibrary from version 4.1.3 to 4.0.10 to support environments running PHP 8.1 or earlier (MTC-31398)
Dynamic Publishing
- Added support for PHP 8.5 (MTC-31010)
- Updated the bundled version of Smarty from 4.5.5 to 4.5.7 (MTC-31542)
JavaScript Libraries
- Updated Svelte, the JavaScript framework used in the Admin screen, from version 4 to version 5 (MTC-29929)
Resolved issues
- Fixed the display position to prevent file thumbnails near the bottom of the list from being cut off at the top of the screen when a large number of Entry assets were registered (MTC-31344)
- Fixed the
Use of uninitialized valuewarning that occurred when theSiteURLConfiguration Directive was undefined (CLOUD-581) - Fixed the checkbox styles on the asset upload screen and theme export screen in the Admin screen theme (
admin2025) (MTC-30460) - Fixed a JavaScript error that occurred when navigating between pages in dialogs, such as the permission assignment and rebuild trigger dialogs (MTC-30587)
- Fixed an issue where an error message could be displayed on the upgrade screen in environments where
DebugModewas set to1(MTC-30675) - Fixed an issue where the
Data Identifier Labelsetting was reset after repeatedly saving on the ContentType editing screen (MTC-31096) - Fixed an issue where the expected warning message was not displayed when viewing a revision containing deleted tags or categories from the revision history of an Entry or Web Page (MTC-31111)
- Fixed an issue where the contents of unused tag fields were lost when restoring an Entry or Web Page from its revision history (MTC-31117)
- Fixed an error that occurred when an undefined value was included during validation of a select box in a ContentField (MTC-31179)
- Fixed an incorrect translation related to ContentData validation (MTC-31184)
- Fixed an issue where the default value of a custom field was not applied when creating a new folder. Also changed the behavior so that the default value is applied when retrieving a value from an object for which the custom field is not set (MTC-31194)
- Changed to display a warning message notifying users that the
Data Identifier Labelsetting was cleared when the required setting was disabled for the assigned field or the field was deleted (MTC-31202) - Fixed issues with HTML tag structures and attribute values in the Admin screen theme (
admin2025), as well as display issues such as broken dropdown menu layouts (MTC-31210) - Fixed an issue where sites and child sites continued to appear without links in the left menu of the dashboard after a user’s permissions were removed (MTC-31293)
- Fixed an error that occurred when filtering the Category Set listing screen by the number of categories or ContentTypes (MTC-31295)
- Fixed an error caused by attempts to retrieve unnecessary columns during initialization in environments where the database schema had changed, such as after an upgrade (MTC-31309)
- Fixed an issue where an upgrade failed because unnecessary columns from the parent site were retrieved during
TrustedHostschecks (MTC-31310) - Fixed an issue where pagination did not work correctly in the list for selecting target ContentTypes on the Rebuild Trigger settings screen (MTC-31314)
- Improved the behavior when removing the required setting from or deleting the field configured as the
Data Identifier Labelon the ContentType editing screen (MTC-31315) - Fixed an issue where the format setting for a
Text (Multi-Line)field was not applied in the ContentData preview (MTC-31322) - Fixed an issue where files were not transferred during server delivery from a Windows environment to another environment, such as Linux, because relative paths were not replaced correctly due to differences in path separators (MTC-31324)
- Fixed
mt-upgrade.cgiandmt-wizard.cgito refer toAdminCGIPathinstead ofCGIPathin PSGI environments (MTC-31326) - Fixed an issue where image files were no longer accepted in an asset field of a ContentType, although files such as PDFs could still be uploaded (MTC-31329)
- Fixed an issue where buttons extended beyond the window and were not visible in the “View Source Code” modal window of MTBlockEditor using TinyMCE 6 (MTC-31333)
- Fixed an issue where the checkbox immediately below was not enabled when the “Always include all options in the export” checkbox was unchecked on the theme export screen (MTC-31338)
- Fixed the
Use of uninitialized valuewarning that occurred when sorting a blog list, such as on the System Log listing screen, when the blog ID was undefined (MTC-31340) - Fixed an issue where themes placed under the directory specified by the
UserThemesDirectoryConfiguration Directive did not appear on the theme listing screen and could not be applied (MTC-31343) - Fixed an error that occurred when rebuilding with the PageBute plugin in Windows environments (MTC-31353)
- Fixed an issue where the
pre_delete_archive_fileandpost_delete_archive_filecallbacks were not called correctly when deleting archive files if theDeleteFilesAfterRebuildConfiguration Directive was set to a true value (MTC-31356) - Fixed an issue where the Change Note was not displayed in the Status section when selecting the latest revision from the Revision History and navigating to the editing screen (MTC-31371)
- Fixed a performance issue when sorting the ContentData listing screen by a ContentField such as the
Data Identifier Label(MTC-31400) - Fixed an issue where the Change Note was not displayed in the Status section when selecting a revision and navigating to the editing screen in mobile view (MTC-31408)
- Fixed an issue where categories were not output in the order shown in the Admin screen when using the
MTSubCategoriestag inside theMTContentFieldtag (MTC-31469) - Fixed an issue in PSGI environments where the values of filter fields (select boxes) in the Admin screen were cached in the language used during the initial access, preventing the display language from switching correctly (MTC-31507)
- Fixed an issue where the process of adding missing default templates during an upgrade generated an excessively large SQL query, which could cause an error in SQL Server (MTC-31520)
- Fixed an issue where archive files could be unintentionally deleted during ContentData updates because processing was performed with an incorrect combination of category and template mapping (MTC-31522)
- Fixed an issue where the contents of the first field entered were lost when creating a new Entry or Web Page in rich text format, alternately entering content in the “Body” and “Extended” fields, and then saving (MTC-31595)
- Fixed an issue where a database error prevented the upgrade from proceeding when a user other than a System administrator was logged in during a version upgrade requiring a schema upgrade (MTC-31598)
- Fixed HTML errors, such as duplicate
idattributes and missing closing tags, on various pages in the Admin screen (MTC-31363) - Changed the conditions under which images from child sites are displayed in the asset list when inserting an image on the Entry editing screen of a parent site or similar screens. Use the
RequireAdministerSiteForChildAssetsConfiguration Directive to restore the previous behavior for backward compatibility (MTC-31517)
AssetUploader
- Fixed to display an appropriate error message when an image format not supported by the system, such as SVG or AVIF, is selected during asset upload (MTC-31127)
- Fixed an issue where searches in the image insertion modal matched only filenames and could not search descriptions or labels when AssetUploader was enabled (MTC-31499)
- Fixed thumbnail preview to keep original aspect ratio at inserting to Image CustomField with AssetUploader, instead of squared on the editing screen (MTC-31512)
- Fixed an issue where images from child sites appeared as options in the parent site’s asset listing when selecting an image field for a ContentType using AssetUploader (MTC-31513)
MTBlockEditor
- Fixed an issue where the state of the “Link to original image” checkbox in an Image block was not correctly reflected when saving while using MTBlockEditor with AssetUploader (MTC-31550)
- Improved MTBlockEditor to use a more generic approach in areas that previously depended on the
mt:commandattribute (MTC-31614)
MTRichTextEditor
- Changed MTRichTextEditor to add
border="1"andstyle="border-collapse: collapse"by default when inserting a table from the toolbar (MTC-31332) - Fixed an issue where styles from Content CSS files were not applied in the boilerplate insertion modal in MTRichTextEditor (MTC-31166)
- Fixed an issue where the
idandclassattributes oftableelements could not be edited correctly in the “HTML Structure Editing Mode” of MTRichTextEditor (MTC-31290) - Fixed an issue where unnecessary line breaks and spaces were inserted when a
rubytag was used in the HTML editing mode of MTRichTextEditor, then HTML editing mode was reopened and the content was saved (MTC-31497) - Fixed an issue where either the text color or background color was reset when both were set and saved in MTRichTextEditor (MTC-31552)
- Fixed an issue where unnecessary
mt-text-blockelements were inserted into the editor DOM when saving from HTML editing mode in MTRichTextEditor (MTC-31555) - Fixed an issue where the results of using the increase and decrease indent buttons were not preserved correctly, and unnecessary
data-mt-indentattributes were added in MTRichTextEditor (MTC-31556) - Fixed an issue in the inline mode of MTRichTextEditor, where the top toolbar is hidden, that caused the link editing toolbars to overlap and become unusable (MTC-31558)
- Adjusted the position and stacking order (
z-index) of the contextual toolbar when editing links in MTRichTextEditor, fixing an issue where it was hidden behind the menu bar and became unusable (MTC-31613) - Fixed an issue on the “System > Rich Text Editor Settings” screen in the Admin screen where rearranging buttons by drag and drop caused duplicate data to be saved, preventing the screen from being displayed (MTC-31622)
- Fixed an issue where the layout of the editing area was changed by the Content CSS settings (MTC-31667)
- Enhanced validation of data retrieved from external sites when embedding Web Pages to allow only the
httpandhttpsschemes (MTC-31413) - Fixed HTML editing mode to prevent entered
i,b,strike, anddelelements from being automatically converted to other elements (MTC-31698) - Fixed an issue in HTML editing mode where a
divelement entered directly under addelement was unintentionally removed when saved (MTC-31697)
Movable Type Advanced
- Fixed an issue in SQL Server where an error occurred when adding a column without a default value during an upgrade (MTC-31532)
Dynamic Publishing
- Improved SQL query construction in Dynamic Publishing (MTC-31304)
- Fixed an issue where the “Dynamic Publishing Error” template was not displayed correctly when accessing a nonexistent URL while using Dynamic Publishing, and the browser’s default error page was displayed instead (MTC-31334)
- Fixed an issue in Dynamic Publishing where an
Invalid tag filtererror occurred when a tag name contained regular expression special characters such as/(MTC-31380)
Security fixes and improvements
- Fixed an issue where CSRF token checks were not performed for the “Publish” and “Unpublish” actions on listing screens such as the Entry listing screen (MTC-31366)
- Fixed a potential OS command injection vulnerability in the
run-periodic-tasksscript (MTC-31369) - Fixed a cross-site scripting (XSS) vulnerability in the restore upload dialog (MTC-31373)
- Fixed an arbitrary code execution (RCE) vulnerability in the
sort_methodmodifier of theMTSubCategoriestag (MTC-31374) - Fixed an arbitrary code execution (RCE) vulnerability during restore upload (MTC-31375)
- Fixed a potential remote code execution (RCE) vulnerability in Dynamic Publishing (MTC-31384)
- Fixed a cross-site scripting (XSS) vulnerability on the ContentType selection screen (MTC-31385)
- Fixed a cross-site scripting (XSS) vulnerability on the Rebuild Trigger settings screen (MTC-31386)
- Fixed a cross-site scripting (XSS) vulnerability on the ContentType Archive Mapping settings screen (MTC-31387)
- Fixed a cross-site scripting (XSS) vulnerability in the
modulemodifier of theMTIncludetag on the template editing screen (MTC-31383) - Fixed a cross-site scripting (XSS) vulnerability in the
blog_idmodifier of theMTIncludetag on the template editing screen (MTC-31388) - Fixed a cross-site scripting (XSS) vulnerability on the ContentData editing and listing screens (MTC-31389)
- Fixed a cross-site scripting (XSS) vulnerability in the Table field of ContentData (MTC-31390)
- Fixed a cross-site scripting (XSS) vulnerability in the “Embedded Text” field of ContentData (MTC-31391)
- Fixed a cross-site scripting (XSS) vulnerability on the template initialization (refresh) screen (MTC-31392)
- Fixed a cross-site scripting (XSS) vulnerability that occurred when importing specially crafted export data (MTC-31393)
- Fixed a cross-site scripting (XSS) vulnerability when outputting the
MTSearchContentTypestag in the ContentData search results template (MTC-31394) - Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 settings on the Web Services settings screen (MTC-31395)
- Fixed a cross-site scripting (XSS) vulnerability in the asset selection dialog of the legacy Block Editor (MTC-31396)
- Fixed a cross-site scripting (XSS) vulnerability in the Image block of the legacy Block Editor (MTC-31397)
- Fixed a cross-site scripting (XSS) vulnerability on the “Basic Authentication Management” screen in the Cloud Edition (MTC-31401)
- Fixed a cross-site scripting (XSS) vulnerability on the “Domain Settings” screen in the Cloud Edition (MTC-31402)
- Fixed a cross-site scripting (XSS) vulnerability on the “Web Server Settings” screen in the Cloud Edition (MTC-31403)
- Fixed a cross-site scripting (XSS) vulnerability on the “Access Restriction Settings” screen in the Cloud Edition (MTC-31404)
- Fixed a cross-site scripting (XSS) vulnerability in the system security settings of the Cloud Edition (MTC-31405)
- Fixed a cross-site scripting (XSS) vulnerability in the bulk user import feature and on the LDAP integration settings screen (MTC-31406)
- Fixed an issue where insufficient CSRF token validation in the Search and Replace feature could cause Entry content to be unintentionally replaced or deleted (MTC-31407)
- Fixed an issue where insufficient CSRF token checks in the asset information update endpoints allowed item information to be updated unintentionally, and deprecated the affected endpoints (
complete_uploadandcomplete_insert) (MTC-31410) - Fixed an issue in the redirect settings of the Cloud Edition where processing continued even when CSRF token validation failed (MTC-31411)
- Fixed an issue in the web server settings of the Cloud Edition where processing continued even when CSRF token validation failed (MTC-31412)
- Fixed an issue in Dynamic Publishing that could lead to arbitrary code execution (RCE) through the
min_scoremodifier of theMTEntriestag (MTC-31415) - Fixed an issue in the WXR file import feature that could allow arbitrary files to be written under the site path (MTC-31416)
- Fixed an issue where invalid SQL could be executed through searches in the Admin screen (MTC-31417)
- Fixed missing permission checks in the template duplication process (MTC-31418)
- Fixed missing permission checks in the asset editing and saving processes (MTC-31419)
- Fixed missing permission checks in the category and folder move processes (MTC-31420)
- Fixed missing permission checks in the bulk update process for Category Sets (MTC-31421)
- Fixed missing permission checks in the “Refresh” action on the template listing screen (MTC-31422)
- Fixed missing permission checks in the folder move process (MTC-31423)
- Fixed missing permission checks in the asset upload cancellation process (MTC-31424)
- Fixed missing permission checks in the endpoint for directly inserting assets (MTC-31425)
- Fixed an issue where the permission check for editing site settings could be bypassed in the generic save process, allowing the Publishing Profile to be changed (MTC-31427)
- Fixed an issue with the order of permission checks on the rebuild start page (MTC-31429)
- Fixed an issue in the Data API stats-related endpoints where users without site permissions could access analytics provider access information (MTC-31430)
- Fixed missing permission checks in the ContentType save process (MTC-31431)
- Fixed missing permission checks in the save and delete processes for banned IP addresses (
BanList) (MTC-31432) - Fixed missing permission checks in the Rebuild Trigger save process (MTC-31434)
- Fixed an issue where the primary category ID of another site could be specified when saving an Entry (MTC-31435)
- Fixed missing permission checks in the user profile image selection process (MTC-31436)
- Fixed an issue in site search (
mt-search.cgi) where malicious SQL could be executed, potentially exposing data including unpublished data (MTC-31457/CVE-2026-103668) - Fixed an issue where an internal redirect could redirect users to a malicious URL when token validation failed and prompted them to sign in again (MTC-31459)
- Fixed an issue where session invalidation checks for session information retrieved from cookies and other sources were insufficient, potentially allowing users to sign in with an invalidated session ID (MTC-31463)
- Fixed an issue where CSRF token checks were not performed for various list actions, including duplicating and refreshing templates and unpublishing ContentData (MTC-31495)
- Fixed an issue in the WXR attachment import feature that could allow file contents to be read (MTC-31510)
- Fixed a cross-site scripting (XSS) vulnerability on the filter listing screen in the Listing Framework (MTC-31534)
- Fixed a cross-site scripting (XSS) vulnerability on the asset listing screen (MTC-31535)
- Fixed a cross-site scripting (XSS) vulnerability in the analytics snippet output (
MTStatsSnippettag) of the Google Analytics 4 plugin (MTC-31536) - Fixed a cross-site scripting (XSS) vulnerability in the tag autocomplete feature for Entries and other objects (MTC-31537)
- Fixed a cross-site scripting (XSS) vulnerability in the asset selection modal of the legacy BlockEditor plugin (MTC-31538)
- Enhanced validation to prevent control characters and disallowed domain formats from being entered in the “Site URL” and “Archive URL” fields when creating a site or changing site settings (MTC-31540)
- Fixed a cross-site scripting (XSS) vulnerability on the theme export screen (MTC-31562)
- Fixed a cross-site scripting (XSS) vulnerability on the rebuild completion pop-up screen (MTC-31563)
- Fixed a cross-site scripting (XSS) vulnerability in the Listing Framework (MTC-31569)
- Fixed a cross-site scripting (XSS) vulnerability in the Google Analytics 4 plugin (MTC-31594)
- Fixed an issue in the upgrade script (
mt-upgrade.cgi) that could allow remote code execution (RCE) or malicious SQL execution (MTC-31703/CVE-2026-96408)
Deprecated features
- Removed the
is_cloudtemplate variable from the System Information screen (MTC-31367) - Deprecated
MT::CMS::Asset::cancel_uploadand added a deprecation warning (MTC-31508) - Deprecated
MT::CMS::Tag::build_tag_tableand added a deprecation warning (MTC-31609)
Acknowledgments
We would like to thank everyone for their contributions to this release, especially those who reported these issues and vulnerabilities. We would also like to thank JPCERT/CC and IPA for their assistance in handling the vulnerability information.
- RyotaK, GMO Flatt Security Inc. (MTC-31457/CVE-2026-103668, MTC-31703/CVE-2026-96408)
- Yujiro Araki (MTC-31117/FEEDBACK-2646)
- Shintaro Kuboki, KANSE Co., Ltd. (MTC-31202/FEEDBACK-2667)
- Seiji Hamagaki (MTC-31497/FEEDBACK-2665)
- Homare Urayama (MTC-31499/FEEDBACK-2666)
- Hatsuru Maegoya, COLSIS, Inc. (MTC-31343/FEEDBACK-2661)
And other reports submitted by anonymous:
- (MTC-31162/FEEDBACK-2650)
- (MTC-31166/FEEDBACK-2651)
- (MTC-31194/FEEDBACK-2655)
- (MTC-31202/FEEDBACK-2657)
- (MTC-31322/FEEDBACK-2658)