A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-24841

CVE-2025-24841: Movable Type Stored XSS Vulnerability

CVE-2025-24841 is a stored XSS flaw in Movable Type's MT Block Editor that allows script execution in logged-in users' browsers. This article covers the technical details, affected versions, impact, and mitigation.

Published: May 26, 2026

CVE-2025-24841 Overview

CVE-2025-24841 is a stored cross-site scripting (XSS) vulnerability in Movable Type, a widely used content management and blogging platform. The flaw resides in the HTML edit mode of the MT Block Editor and is exploitable when TinyMCE6 is configured as the rich text editor. An authenticated attacker with content authoring privileges can inject malicious script content that executes in the browser of any logged-in user who views the affected content. The vulnerability is tracked under [CWE-79] (Improper Neutralization of Input During Web Page Generation).

Critical Impact

Stored XSS enables session hijacking, credential theft, and unauthorized actions performed in the context of authenticated Movable Type users, including administrators.

Affected Products

  • Movable Type (versions prior to MT 8.4.2 / corresponding fixed releases)
  • Movable Type instances using the MT Block Editor with HTML edit mode enabled
  • Movable Type deployments configured with TinyMCE6 as the rich text editor

Discovery Timeline

  • 2025-02-19 - CVE-2025-24841 published to the National Vulnerability Database
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2025-24841

Vulnerability Analysis

The vulnerability arises in the HTML edit mode of the MT Block Editor when TinyMCE6 handles rich text input. The editor accepts HTML markup directly from authenticated authors but fails to neutralize script-bearing constructs before storing and later rendering the content. When another logged-in user views the affected post, page, or editor preview, the injected payload executes in their browser session.

Because the payload is stored server-side, the attack persists across sessions and reaches any user who loads the affected resource. The CVSS vector indicates the scope changes upon successful exploitation, meaning the impact crosses from the authoring component into the viewing user's browser context. User interaction is required, typically loading the malicious post in an authenticated session.

Root Cause

The root cause is improper neutralization of HTML and JavaScript content submitted through the TinyMCE6-backed HTML edit mode. The MT Block Editor trusts the rich text input from authenticated authors and does not strip or encode script-capable elements such as <script> tags, event handler attributes, or javascript: URIs before persisting them.

Attack Vector

An attacker requires low-privilege authenticated access, such as a content author or contributor role. The attacker creates or edits content using the HTML edit mode of the MT Block Editor and embeds a malicious payload. When an administrator or another logged-in user opens the content, the script executes with that victim's privileges, enabling session token theft, CSRF-style actions, account takeover, or pivoting to administrative functions.

No verified public proof-of-concept exists for this issue. Refer to the JVN Security Advisory JVN48742353 and the Movable Type Release Announcement MT-8.4.2 for vendor-provided technical context.

Detection Methods for CVE-2025-24841

Indicators of Compromise

  • Stored content in Movable Type entries, pages, or template modules containing <script> tags, inline event handlers such as onerror, onload, onclick, or javascript: URIs introduced through the Block Editor
  • Unexpected outbound requests from administrator browsers to attacker-controlled domains shortly after viewing Movable Type content
  • Anomalous session token usage or administrative actions performed from unusual IP addresses after content review activity

Detection Strategies

  • Audit the Movable Type database for entries created or modified through MT Block Editor HTML mode and search for HTML elements or attributes capable of executing JavaScript
  • Review web server access logs for requests to Movable Type editor endpoints originating from low-privilege accounts followed by administrator views of the same content
  • Inspect browser security telemetry and Content Security Policy violation reports generated when administrators load editor previews or published entries

Monitoring Recommendations

  • Monitor Movable Type authoring activity, especially edits performed by lower-privilege roles, and alert on insertions of <script>, <iframe>, or event-handler attributes
  • Track administrator session anomalies including new sessions, password changes, and privilege modifications that follow content viewing events
  • Enable and review Content Security Policy reporting to surface unexpected script sources executing in the Movable Type admin interface

How to Mitigate CVE-2025-24841

Immediate Actions Required

  • Upgrade Movable Type to the fixed release identified in the Movable Type MT-8.4.2 announcement and apply equivalent patches for supported branches
  • Review all content created or edited through the MT Block Editor HTML mode since the editor was deployed and remove any unauthorized script content
  • Audit user accounts with authoring privileges and reset credentials for any accounts that may have been used to plant payloads

Patch Information

Movable Type addressed the issue in the release announced as MT-8.4.2. Administrators should consult the vendor advisory at JVN48742353 for the complete list of fixed versions across Movable Type product branches and apply the corresponding update.

Workarounds

  • Restrict use of the MT Block Editor HTML edit mode to fully trusted administrative users until the patch is applied
  • Disable TinyMCE6 as the active rich text editor where feasible, reverting to a configuration not affected by the issue
  • Enforce a strict Content Security Policy on the Movable Type admin interface to block inline scripts and untrusted script sources, reducing the impact of any stored payloads
bash
# Example restrictive Content Security Policy header for the Movable Type admin interface
Header set Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeXSS

  • Vendor/TechMovable Type

  • SeverityMEDIUM

  • CVSS Score5.4

  • EPSS Probability0.23%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityLow
  • AvailabilityNone
  • CWE References
  • CWE-79
  • Technical References
  • JVN Security Advisory JVN48742353

  • Movable Type Release Announcement MT-842
  • Related CVEs
  • CVE-2026-22875: Movable Type Stored XSS Vulnerability

  • CVE-2026-21393: Movable Type Stored XSS Vulnerability

  • CVE-2026-44392: Movable Type Auth Bypass Vulnerability

  • CVE-2026-25776: Movable Type RCE Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English