Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.37% | — | MogublogAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve… | |
| Aplazada | Media (5.3) | 0.37% | — | MogublogAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators. | |
| Aplazada | Media (6.9) | 0.45% | — | MogublogAI | 11/9/2026 | 15/9/2026 | MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user identifier to suppress reply… | |
| Aplazada | Alta (8.7) | 0.54% | — | MogublogAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from… | |
| Aplazada | Media (6.9) | 0.83% | — | MogublogAIElasticsearchAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious… | |
| Aplazada | Alta (8.7) | 0.73% | — | MogublogAIDom4jAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions.… | |
| Aplazada | Media (5.5) | 0.47% | — | Mogublog Mogu BlogAI | 20/4/2026 | 17/6/2026 | A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Storage Service. The… | |
| Analizada | Baja (2.1) | 0.63% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile of the component ZIP File Handler. Such manipulation of the argument fileUrl leads to path traversal. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.38% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload. The attack may be initiated remotely. The exploit has been made available to the public and could be… | |
| Analizada | Media (5.5) | 0.53% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may… | |
| Analizada | Baja (2.9) | 0.47% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The attack can be initiated remotely. The attack's complexity is rated as high. The… | |
| Modificada | Media (6.5) | 0.85% | — | Mogublog Project Mogublog | 15/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal. The attack may be initiated remotely. The… | |
| Modificada | Media (6.1) | 0.64% | — | Mogublog Project Mogublog | 12/7/2022 | 17/6/2026 | Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS). |