← Back to CVE List
CVE-2026-90567NVD
Description
A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.
CVSS Base Metrics
CVSS v3 (3.1)
LOW 3.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
CVSS v4 (4.0)
MEDIUM 5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Affected & Patched Versions
| Product | Affected Versions | Patched Version |
|---|---|---|
| quequnlong shiyi-blog | 1.2.0, 1.2.1 | N/A |