Vulnerabilities
Summary — last 7 days
New vulnerabilities2,743▲ 32 vs. last week
Critical / high1,477▲ 367 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
22 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.37% | — | MogublogAI | 9/11/2026 | 9/11/2026 | MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve… | |
| Deferred | Medium (5.3) | 0.37% | — | MogublogAI | 9/11/2026 | 9/11/2026 | MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators. | |
| Deferred | Medium (6.9) | 0.45% | — | MogublogAI | 9/11/2026 | 9/15/2026 | MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user identifier to suppress reply… | |
| Deferred | High (8.7) | 0.54% | — | MogublogAI | 9/11/2026 | 9/11/2026 | MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from… | |
| Deferred | Medium (6.9) | 0.83% | — | MogublogAIElasticsearchAI | 9/11/2026 | 9/11/2026 | MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious… | |
| Deferred | High (8.7) | 0.73% | — | MogublogAIDom4jAI | 9/11/2026 | 9/11/2026 | MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions.… | |
| Deferred | Medium (5.5) | 0.47% | — | Mogublog Mogu BlogAI | 4/20/2026 | 6/17/2026 | A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Storage Service. The… | |
| Analyzed | Low (2.1) | 0.63% | — | Mogublog Project Mogublog | 12/1/2025 | 9/25/2026 | A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile of the component ZIP File Handler. Such manipulation of the argument fileUrl leads to path traversal. The attack may be launched remotely. The… | |
| Analyzed | Low (2.1) | 0.38% | — | Mogublog Project Mogublog | 12/1/2025 | 9/25/2026 | A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload. The attack may be initiated remotely. The exploit has been made available to the public and could be… | |
| Analyzed | Medium (5.5) | 0.53% | — | Mogublog Project Mogublog | 12/1/2025 | 9/25/2026 | A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may… | |
| Analyzed | Low (2.9) | 0.47% | — | Mogublog Project Mogublog | 12/1/2025 | 9/25/2026 | A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The attack can be initiated remotely. The attack's complexity is rated as high. The… | |
| Modified | Medium (6.5) | 0.85% | — | Mogublog Project Mogublog | 4/15/2023 | 6/17/2026 | A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal. The attack may be initiated remotely. The… | |
| Modified | Medium (6.1) | 0.64% | — | Mogublog Project Mogublog | 7/12/2022 | 6/17/2026 | Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS). | |
| Modified | Critical (9.8) | 2.8% | — | Axublog | 5/4/2018 | 6/17/2026 | Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php file. | |
| Modified | High (7.5) | 1.2% | — | Uapplication Ublog | 2/6/2007 | 6/16/2026 | SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modified | Medium (4.3) | 2.0% | — | Uapplication Ublog Reload | 2/6/2007 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (2) badword.asp, (3) polls.asp,… | |
| Modified | Medium (5.8) | 1.5% | — | Uapplication Ublog | 5/9/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via text fields when adding a blog entry. | |
| Modified | High (7.5) | 1.2% | — | Ublog Reload | 6/20/2005 | 6/16/2026 | Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp. | |
| Modified | Medium (4.3) | 3.6% | — | Uapplication Ublog Reload | 6/20/2005 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter. | |
| Modified | Medium (5) | 1.5% | — | Uapplication Ublog ReloadAI | 5/3/2005 | 6/16/2026 | Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb). | |
| Modified | Medium (4.3) | 2.0% | — | Ublog ReloadAI | 5/2/2005 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modified | Medium (5) | 1.4% | — | Uapplication Ublog Reload | 5/2/2005 | 6/16/2026 | Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb. |