MEDIUMVulnerability

CVE-2026-90527

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.

Properties

severity
MEDIUM
score
4.3
cve_id
CVE-2026-90527
signal_observed_at
2026-09-23T04:35:40+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
published_at
2026-09-13T15:16:28.487
last_modified
2026-09-16T15:18:28.913

Related Entities (3)

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
[Weakness]Improper Control of Generation of Code ('Code Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90527 — Ninja Signal Threat Intelligence | Ninja Signal