---
id: CVE-2026-90568
title: A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2
summary: >-
  A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects
  the function BlogSortServiceImpl.addBlogSort of the file
  mogu_web/src/main/resources/templates/info.ftl of the component blogSort
  Endpoint. The manipulation of …
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: moxi624
product: Mogu Blog v2
affected:
  - mogu_blog_v2 4.0
  - mogu_blog_v2 4.1
  - mogu_blog_v2 4.2
  - mogu_blog_v2 4.3
  - mogu_blog_v2 4.4
  - mogu_blog_v2 4.5
  - mogu_blog_v2 5.0
  - mogu_blog_v2 5.1
  - mogu_blog_v2 5.2
published: '2026-09-13'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:17:39.480'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90568'
references:
  - url: 'https://gitee.com/moxi159753/mogu_blog_v2/issues/IK5STW'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90568'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/912672'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403153'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403153/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
epss: 0.00331
epssPercentile: 0.23441
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T19:42:52.814790Z'
ingestedAt: '2026-09-14T15:23:07.469Z'
---

## Overview

A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross site scripting. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
