CVE-2026-90568 | moxi624 Mogu Blog v2 up to 5.2 blogSort Endpoint info.ftl BlogSortServiceImpl.addBlogSort sortName cross site scripting (IK5STW)

SecurityVulns

A vulnerability categorized as problematic has been discovered in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross site scripting.

This vulnerability is reported as CVE-2026-90568. The attack can be launched remotely. No exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More