๐Ÿ” CVE Alert

CVE-2026-90527

MEDIUM 4.3

quequnlong shiyi-blog Add Message API index.vue cross site scripting

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-79 CWE-94
Vendor quequnlong
Product shiyi-blog
Published Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for quequnlong shiyi-blog

Be the first to know when new medium vulnerabilities affecting quequnlong shiyi-blog are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

quequnlong / shiyi-blog
1.2.0 1.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/403117 vuldb.com: https://vuldb.com/vuln/403117/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90527 vuldb.com: https://vuldb.com/submit/912534 gitee.com: https://gitee.com/quequnlong/shiyi-blog/issues/IK5RF6 gitee.com: https://gitee.com/quequnlong/shiyi-blog/

Credits

๐Ÿ” JunRoinxxX (VulDB User) VulDB CNA Team