Vulnerabilidades en moxi624
9 resultadosAnálisis Vexday
O fornecedor moxi624 apresenta footprint reduzido com apenas 2 CVEs registradas na base, nenhuma delas sob ataque ativo ou com severity crítica no momento. O risco atual é baixo, sem publicações recentes que indiquem evolução da superfície de ataque, embora a fraqueza dominante (CWE-36 - Path Traversal) mereça monitoramento em novas versões.
CVE-2023-2101MEDIUMmoxi624 Mogu Blog v2 uploadPicsByUrl uploadPictureByUrl absolute path traversalEPSS 0.8%CVE-2026-89261MEDIUMMoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management EndpointsEPSS 0.8%CVE-2026-89260HIGHMoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback EndpointEPSS 0.7%CVE-2026-89262HIGHMoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership CheckEPSS 0.5%CVE-2026-6625MEDIUMmoxi624 Mogu Blog v2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceImpl.uploadPictureByUrl server-side request forgeryEPSS 0.5%CVE-2026-89263MEDIUMMoguBlog through 6.2 Missing Authentication on the Comment Email-Notification EndpointEPSS 0.5%CVE-2026-89265MEDIUMMoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid EndpointEPSS 0.4%CVE-2026-89264MEDIUMMoguBlog through 6.2 Comment Author Spoofing via Request-Body IdentityEPSS 0.4%CVE-2026-90568MEDIUMmoxi624 Mogu Blog v2 blogSort Endpoint info.ftl BlogSortServiceImpl.addBlogSort cross site scriptingEPSS 0.3%