CVE-2026-90568Low· 3.5▾ SunlitA vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross site scripting. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89265Medium· 4.3MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint
CVE-2026-89260High· 7.5MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint
CVE-2026-89262High· 7.5MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check
CVE-2026-89261Medium· 6.5MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints
CVE-2026-89264Medium· 4.3MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user
CVE-2026-89263Medium· 5.3MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users