Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89260— MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint

Quick assessment

Affected
moxi624 MoguBlog
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MoguBlog 版本 6.2 及以下存在 XML 外部实体(XXE)注入漏洞,位于微信回调处理程序中的 POST /wechat/wechatCheck 接口。 方法将原始请求体直接传递给 ,而该方法内部使用的 dom4j 未经过加固,未对 DTD 声明或外部实体引用进行限制。未经认证的远程攻击者可通过在 XML 中注入包含外部参数实体的 DOCTYPE 声明,从而读取任意本地文件或触发出站 HTTP 请求;已解析的实体内容会在错误响应中反映出来。

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89260

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter entities to read arbitrary local files or trigger outbound HTTP requests, with resolved entities reflected in error responses.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
XML外部实体引用的不恰当限制(XXE)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
moxi624 MoguBlog 0 ~ 6.2 -

II. Public POCs for CVE-2026-89260

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89260

登录查看更多情报信息。

Vendor Advisories for CVE-2026-89260 (1)

Proof of Concept for CVE-2026-89260 (1)

Other References for CVE-2026-89260 (2)

Same Patch Batch · moxi624 · 2026-09-11 · 6 CVEs total

CVE-2026-89262 7.5 HIGH MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check
CVE-2026-89261 6.5 MEDIUM MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints
CVE-2026-89263 5.3 MEDIUM MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint
CVE-2026-89264 4.3 MEDIUM MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity
CVE-2026-89265 4.3 MEDIUM MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint

IV. Related Vulnerabilities

V. Comments for CVE-2026-89260

No comments yet


Leave a comment