VYPR
Vendor

Mogublog Project

Products
1
CVEs
11
Across products
11
Status
Private

Products

1

Recent CVEs

11
  • CVE-2026-89262HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.01

    MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment…

  • CVE-2026-89260HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.01

    MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or…

  • CVE-2025-13814HigDec 1, 2025
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit…

  • CVE-2026-89261MedSep 11, 2026
    risk 0.42cvss 6.5epss 0.01

    MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete…

  • CVE-2025-13816MedDec 1, 2025
    risk 0.41cvss 6.3epss 0.01

    A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile of the component ZIP File Handler. Such manipulation of the argument fileUrl leads to path traversal. The…

  • CVE-2025-13815MedDec 1, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload. The attack may be initiated remotely. The exploit has been made…

  • CVE-2022-30517MedJul 12, 2022
    risk 0.40cvss 6.1epss 0.01

    Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2025-13813MedDec 1, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The attack can be initiated remotely. The attack's…

  • CVE-2026-89263MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user…

  • CVE-2026-89265MedSep 11, 2026
    risk 0.28cvss 4.3epss 0.00

    MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions…

  • CVE-2023-2101MedApr 15, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal.…