CVE-2026-90567: Quequnlong Shiyi-Blog

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.

Affected products

  • Quequnlong Shiyi-Blog: version 1.2.0 only; version 1.2.1 only

Published 2026-09-13. Last modified 2026-09-15.