CVE Watchtower

← Back to CVE List

CVE-2026-90563NVD

Description

A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely.
Severity Level
LOW (3.5)
Published Date
13/09/2026
Last Modified
16/09/2026
Exploitation Status
????
EPSS Score
0.20% (percentile 10.6%)

CVSS Base Metrics

CVSS v3 (3.1)
LOW 3.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
CVSS v4 (4.0)
MEDIUM 5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X

Weaknesses (CWE)

CWE-79 - Cross Site ScriptingCWE-94 - Code Injection

Affected & Patched Versions

ProductAffected VersionsPatched Version
maliangnansheng bbs-springboot3.0.0N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.