All 6 CVE vulnerabilities found in MoguBlog, with AI-generated Chinese analysis, references, and POCs.
Vendor: moxi624
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-89264 | MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity CWE-639 | 4.3 | Medium | 2026-09-11 |
| CVE-2026-89265 | MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint CWE-862 | 4.3 | Medium | 2026-09-11 |
| CVE-2026-89263 | MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint CWE-306 | 5.3 | Medium | 2026-09-11 |
| CVE-2026-89262 | MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check CWE-639 | 7.5 | High | 2026-09-11 |
| CVE-2026-89260 | MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint CWE-611 | 7.5 | High | 2026-09-11 |
| CVE-2026-89261 | MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints CWE-306 | 6.5 | Medium | 2026-09-11 |
All 6 known CVE vulnerabilities affecting MoguBlog with full Chinese analysis, references, and POCs where available.