VulnSea

MoguBlog vulnerabilities

CVEs whose affected-version data names the MoguBlog package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-89265Medium· 4.3PoC
1w ago

MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint

MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office …

Twilightmoxi624 · MoguBlogEPSS 0.21%via CVEORG
CVE-2026-89260High· 7.5PoC
1w ago

MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint

MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an u…

Midnightmoxi624 · MoguBlogEPSS 0.43%via CVEORG
CVE-2026-89262High· 7.5PoC
1w ago

MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary commen…

Midnightmoxi624 · MoguBlogEPSS 0.31%via CVEORG
CVE-2026-89261Medium· 6.5PoC
1w ago

MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints t…

Twilightmoxi624 · MoguBlogEPSS 0.46%via CVEORG
CVE-2026-89264Medium· 4.3PoC
1w ago

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the re…

Twilightmoxi624 · MoguBlogEPSS 0.21%via NVD
CVE-2026-89263Medium· 5.3PoC
1w ago

MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users

MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotif…

Twilightmoxi624 · MoguBlogEPSS 0.26%via NVD
CVE-2025-13816Medium· 6.3
9mo ago

A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2

A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile of the component ZIP File Handler. Such manipulation of the argu…

Sunlitmogublog_project · mogublogEPSS 0.63%via NVD
CVE-2025-13815Medium· 6.3
9mo ago

A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2

A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload. The attack may be initia…

Sunlitmogublog_project · mogublogEPSS 0.38%via NVD
CVE-2025-13814High· 7.3
9mo ago

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The at…

Twilightmogublog_project · mogublogEPSS 0.53%via NVD
CVE-2025-13813Medium· 5.6
9mo ago

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The atta…

Sunlitmogublog_project · mogublogEPSS 0.47%via NVD
MoguBlog vulnerabilities (CVEs) · VulnSea