CVE-2025-62499
Last modified
CVE-2025-62499 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit CategorySet of ContentType page.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit CategorySet of ContentType page.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-62499?
How severe is CVE-2025-62499?
How do I fix CVE-2025-62499?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-62493A vulnerability exists in the QuickJS engine's BigInt string…6.5
- CVE-2025-62494A type confusion vulnerability exists in the handling of the…8.8
- CVE-2025-62495An integer overflow vulnerability exists in the QuickJS regu…8.8
- CVE-2025-62496A vulnerability exists in the QuickJS engine's BigInt string…8.8
- CVE-2025-62497Cross-site request forgery vulnerability exists in SNC-CX600…6.5
- CVE-2025-62498A relative path traversal (ZipSlip) vulnerability was discov…8.8
- CVE-2025-6250Prior to 25.4.270.0, when wmic.exe is elevated with a full a…6.7
- CVE-2025-62500An out-of-bounds read vulnerability exists in the EMF functi…7.1
- CVE-2025-62501SSH Hostkey misconfiguration vulnerability in TP-Link Archer…8.1
- CVE-2025-62503User with CREATE and no UPDATE privilege for Pools, Connecti…4.6
- CVE-2025-62504Envoy is an open source edge and service proxy. Envoy versio…7.5
- CVE-2025-62505LobeChat is an open source chat application platform. The we…3
Are you affected by CVE-2025-62499?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
