CVE-2026-89260

MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter entities to read arbitrary local files or trigger outbound HTTP requests, with resolved entities reflected in error responses.

  • Published Sep 11, 2026
  • CVSS 8.7 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-89260 at the National Vulnerability Database