CVE-2026-90568: moxi624 Mogu Blog v2 blogSort Endpoint info.ftl BlogSortServiceImpl.addBlogSort cross site scripting
A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file moguweb/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross site scripting. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments are reported to be affected?
The affected product is moxi624 Mogu Blog v2 through version 5.2. The issue is associated with the blogSort endpoint.
What does an attacker need to exploit this issue?
The attack can be launched remotely, but the supplied severity vector indicates an attacker needs low-level privileges and user interaction. Exploitation involves controlling the sortName argument.
What is the expected security impact?
The supplied assessment indicates low integrity impact, with no confidentiality or availability impact. The reported weakness is cross-site scripting.
Is there a vendor response or confirmed remediation status?
The project was reportedly notified early through an issue report but had not responded at the time of publication. The provided data does not identify a fixed version or workaround.