SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90567

LOW · CVSS 3.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

A cross-site scripting vulnerability exists in the highlightKeyword function of the Search component in quequnlong shiyi-blog versions up to 1.2.1, allowing attackers to manipulate the title or summary arguments. This can lead to remote code execution through malicious scripts. Developers and administrators using affected versions should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-90567
Severity
LOW
CVSS
3.5
EPSS
N/A

Original NVD Description

A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.