VYPR

mogu_blog_v2

by Moxi624

CVEs (3)

  • CVE-2022-27047CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.01

    mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation.

  • CVE-2026-6625HigApr 20, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the…

  • CVE-2023-2101MedApr 15, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal.…