SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90564

LOW · CVSS 3.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

A cross-site scripting vulnerability exists in the chat sendMsg endpoint of quequnlong shiyi-blog versions 1.0.0 to 1.2.1, specifically within the SysChatMsgMapper.getChatMsgList function. This flaw allows remote attackers to manipulate the chat_msg argument, potentially leading to the execution of malicious scripts in users' browsers. Developers and administrators using affected versions should prioritize remediation to protect users from potential exploitation.

CVE
CVE-2026-90564
Severity
LOW
CVSS
3.5
EPSS
N/A

Original NVD Description

A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.