Vulnerabilities

Summary — last 7 days

New vulnerabilities2,743▲ 32 vs. last week
Critical / high1,477▲ 367 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

22 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.3)0.37%—MogublogAI9/11/20269/11/2026
MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve…
DeferredMedium (5.3)0.37%—MogublogAI9/11/20269/11/2026
MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.
DeferredMedium (6.9)0.45%—MogublogAI9/11/20269/15/2026
MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user identifier to suppress reply…
DeferredHigh (8.7)0.54%—MogublogAI9/11/20269/11/2026
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from…
DeferredMedium (6.9)0.83%—MogublogAIElasticsearchAI9/11/20269/11/2026
MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious…
DeferredHigh (8.7)0.73%—MogublogAIDom4jAI9/11/20269/11/2026
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions.…
DeferredMedium (5.5)0.47%—Mogublog Mogu BlogAI4/20/20266/17/2026
A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Storage Service. The…
AnalyzedLow (2.1)0.63%—Mogublog Project Mogublog12/1/20259/25/2026
A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile of the component ZIP File Handler. Such manipulation of the argument fileUrl leads to path traversal. The attack may be launched remotely. The…
AnalyzedLow (2.1)0.38%—Mogublog Project Mogublog12/1/20259/25/2026
A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload. The attack may be initiated remotely. The exploit has been made available to the public and could be…
AnalyzedMedium (5.5)0.53%—Mogublog Project Mogublog12/1/20259/25/2026
A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may…
AnalyzedLow (2.9)0.47%—Mogublog Project Mogublog12/1/20259/25/2026
A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The attack can be initiated remotely. The attack's complexity is rated as high. The…
ModifiedMedium (6.5)0.85%—Mogublog Project Mogublog4/15/20236/17/2026
A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal. The attack may be initiated remotely. The…
ModifiedMedium (6.1)0.64%—Mogublog Project Mogublog7/12/20226/17/2026
Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS).
ModifiedCritical (9.8)2.8%—Axublog5/4/20186/17/2026
Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php file.
ModifiedHigh (7.5)1.2%—Uapplication Ublog2/6/20076/16/2026
SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModifiedMedium (4.3)2.0%—Uapplication Ublog Reload2/6/20076/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (2) badword.asp, (3) polls.asp,…
ModifiedMedium (5.8)1.5%—Uapplication Ublog5/9/20066/16/2026
Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via text fields when adding a blog entry.
ModifiedHigh (7.5)1.2%—Ublog Reload6/20/20056/16/2026
Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.
ModifiedMedium (4.3)3.6%—Uapplication Ublog Reload6/20/20056/16/2026
Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.
ModifiedMedium (5)1.5%—Uapplication Ublog ReloadAI5/3/20056/16/2026
Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).
ModifiedMedium (4.3)2.0%—Ublog ReloadAI5/2/20056/16/2026
Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModifiedMedium (5)1.4%—Uapplication Ublog Reload5/2/20056/16/2026
Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb.