---
id: CVE-2026-90527
title: A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1
summary: >-
  A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is
  an unknown function of the file blog-admin/src/views/message/message/index.vue
  of the component Add Message API. The manipulation of the argument
  body.content…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: quequnlong
product: shiyi-blog
affected:
  - shiyi-blog 1.2.0
  - shiyi-blog 1.2.1
published: '2026-09-13'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:18:28.913'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90527'
references:
  - url: 'https://gitee.com/quequnlong/shiyi-blog/'
    label: cna@vuldb.com
  - url: 'https://gitee.com/quequnlong/shiyi-blog/issues/IK5RF6'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90527'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/912534'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403117'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403117/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
epss: 0.0047
epssPercentile: 0.37983
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T14:10:04.290902Z'
ingestedAt: '2026-09-14T15:23:07.469Z'
---

## Overview

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
