Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter entities to read arbitrary local files or trigger outbound HTTP requests, with resolved entities reflected in error responses. | |
| Title | MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint | |
| First Time appeared |
Mogublog Project
Mogublog Project mogublog |
|
| Weaknesses | CWE-611 | |
| CPEs | cpe:2.3:a:mogublog_project:mogublog:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mogublog Project
Mogublog Project mogublog |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T15:25:15.767Z
Reserved: 2026-09-11T10:52:56.668Z
Link: CVE-2026-89260
No data.
Status : Received
Published: 2026-09-11T16:17:50.560
Modified: 2026-09-11T16:17:50.560
Link: CVE-2026-89260
No data.
OpenCVE Enrichment
No data.
-
CWE-611
Improper Restriction of XML External Entity Reference