CVE-2026-90527: quequnlong shiyi-blog Add Message API index.vue cross site scripting
A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which versions should be treated as affected?
quequnlong shiyi-blog versions up to and including 1.2.1 are reported as affected. The available information does not identify a fixed version.
Does exploitation require an authenticated attacker or victim interaction?
The attack can be executed remotely and the vector indicates no attacker privileges are required. It also requires user interaction, meaning a victim must interact with attacker-controlled content for the cross-site scripting to take effect.
What is the reported security impact?
The supplied vector rates the impact as low integrity impact, with no reported confidentiality or availability impact. The vulnerable input is the body.content argument handled by the Add Message API component.
Is a vendor response or workaround available?
The project was reportedly notified early through an issue report but had not responded at the time of publication. No workaround, configuration mitigation, or patch version is provided in the available data.