{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90527","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-09-12T11:01:01.865Z","datePublished":"2026-09-13T14:15:19.964Z","dateUpdated":"2026-09-16T14:10:15.646Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-09-13T14:15:19.964Z"},"title":"quequnlong shiyi-blog Add Message API index.vue cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"Cross Site Scripting"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"Code Injection"}]}],"affected":[{"vendor":"quequnlong","product":"shiyi-blog","versions":[{"version":"1.2.0","status":"affected"},{"version":"1.2.1","status":"affected"}],"cpes":["cpe:2.3:a:quequnlong:shiyi-blog:*:*:*:*:*:*:*:*"],"modules":["Add Message API"]}],"descriptions":[{"lang":"en","value":"A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":4.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N/E:ND/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-09-12T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-09-12T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-09-12T13:06:07.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"JunRoinxxX (VulDB User)","type":"reporter"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/403117","name":"VDB-403117 | quequnlong shiyi-blog Add Message API index.vue cross site scripting","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/403117/cti","name":"VDB-403117 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-90527","name":"CVE-2026-90527 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/912534","name":"Submit #912534 | quequnlong shiyi-blog 1.0.0 through 1.2.1; source through 4db96f9 Cross Site Scripting","tags":["third-party-advisory"]},{"url":"https://gitee.com/quequnlong/shiyi-blog/issues/IK5RF6","tags":["issue-tracking"]},{"url":"https://gitee.com/quequnlong/shiyi-blog/","tags":["product"]}],"x_generator":["VulDB PVTS v202609"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-16T14:10:04.290902Z","id":"CVE-2026-90527","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-16T14:10:15.646Z"}}]}}