CVE-2026-90567

Summary

A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.

Affected Software

VendorProductVersion RangeStatus
quequnlongshiyi-blog1.2.0affected
quequnlongshiyi-blog1.2.1affected

Weaknesses

  • CWE-79: Cross Site Scripting
  • CWE-94: Code Injection

References