moxi624 MoguBlog
6 known vulnerabilities in moxi624 MoguBlog, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-89265 CVSS 5.3 medium MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the…
- CVE-2026-89264 CVSS 5.3 medium MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to…
- CVE-2026-89263 CVSS 6.9 medium MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated…
- CVE-2026-89262 CVSS 8.7 high MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks…
- CVE-2026-89261 CVSS 6.9 medium MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote…
- CVE-2026-89260 CVSS 8.7 high MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck…