MEDIUM 5.1 NVD
CVE-2026-90567
A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/sr
A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.
References
- https://gitee.com/quequnlong/shiyi-blog/
- https://gitee.com/quequnlong/shiyi-blog/issues/IK5SPD
- https://vuldb.com/cve/CVE-2026-90567
- https://vuldb.com/submit/912671
- https://vuldb.com/vuln/403152
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-09-13 via NVD.
vulnfeed aggregates 13636 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.