
CVE-2026-21393 Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an attacker, arbitrary script may be executed on a lo… https://www.cve.org/CVERecord?id=CVE-2026-21393
Post summary
The post announces a stored XSS flaw in Movable Type’s Edit Comment that could allow arbitrary script execution, without mentioning any PoC, exploit, patch, or evidence of active exploitation.

