GHSA-8g7w-hw7q-6jwqMediumCVSS 3.5
A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this...
🔗 CVE IDs covered (1)
📋 Description
A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-90567
- https://gitee.com/quequnlong/shiyi-blog
- https://gitee.com/quequnlong/shiyi-blog/issues/IK5SPD
- https://vuldb.com/cve/CVE-2026-90567
- https://vuldb.com/submit/912671
- https://vuldb.com/vuln/403152
- https://vuldb.com/vuln/403152/cti
- https://github.com/advisories/GHSA-8g7w-hw7q-6jwq