CVE-2025-22888

CVSS 3.0 Score 5.4 of 10 (medium)

Details

Published Feb 19, 2025
CWE ID 79

Summary

CVE-2025-22888 is a stored cross-site scripting (XSS) vulnerability affecting Movable Type's custom block edit page in MT Block Editor. An attacker can inject malicious scripts into a targeted website, which, if exploited, can be executed on a logged-in user's web browser. The vulnerability poses a serious threat, as it allows an attacker to gain unauthorized access to sensitive data, perform actions on behalf of the user, or redirect the user to malicious websites. Movable Type users are advised to update their software to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share