CVE-2026-90563: maliangnansheng bbs-springboot ArticleController.java utils.toToc cross site scripting
Published Sep 13, 2026
·Updated
A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely.
Affected Software
1 affected component
maliangnansheng/bbs-springboot=3.0.0
Event History
Sep 13, 2026
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that the attacker needs low-level privileges. Exploitation can be performed remotely.
2
Does exploitation require action from another user, and what is the expected impact?
The CVSS vector indicates that user interaction is required. The stated impact is limited to integrity; no confidentiality or availability impact is identified.