Mogublog Project maintains a focused blogging platform where vulnerabilities skew strongly toward critical-severity outcomes. The exposure recurs through file-path and access-control weaknesses—including absolute path traversal, improper authorization, and cross-site scripting—that are characteristic of web applications handling user-supplied input and authentication boundaries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mogublog Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13814CRITICAL A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The ma | Dec 1, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-13815CRITICAL A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filed | Dec 1, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-13816HIGH A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile of the | Dec 1, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-13813HIGH A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. | Dec 1, 2025 | 8.1 | 27 | NO | NO |
CVE-2023-2101MEDIUM A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture | Apr 15, 2023 | 6.5 | 22 | NO | NO |
CVE-2022-30517MEDIUM Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS). | Jul 12, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mogublog Project.
Media articles that mention a CVE ID that affects a product developed by Mogublog Project — matched by CVE ID, not by vendor name.