Description
A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.
Published: 2026-09-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: cross-site scripting
Action: Patch
AI Analysis

Impact

The vulnerability is an XSS flaw located in the highlightKeyword function of the Search component in shiyi‑blog. The function renders the title or summary field without proper sanitization, so an attacker can supply malicious input that is executed as script in the victim’s browser.

Affected Systems

Affected products are quequnlong:shiyi-blog up The flaw resides in the blog‑web component under components/Search. All releases up to 1.2.1 are vulnerable.

Risk and Exploitability

The CVSS score of 5.1 denotes moderate severity. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The description states the attack can be initiated remotely; exploitation results in client‑side script execution in the context of the web interface.

Generated by OpenCVE AI on September 15, 2026 at 16:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a release newer than 1.2.1.
  • Apply input validation or output sanitization so that title and summary fields are escaped or forbidden from containing JavaScript.
  • Configure a strong Content‑Security‑Policy to restrict script execution from untrusted sources.

Generated by OpenCVE AI on September 15, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.
Title quequnlong shiyi-blog Search index.vue highlightKeyword cross site scripting
First Time appeared Quequnlong
Quequnlong shiyi-blog
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:quequnlong:shiyi-blog:*:*:*:*:*:*:*:*
Vendors & Products Quequnlong
Quequnlong shiyi-blog
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Quequnlong Shiyi-blog
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:59:38.713Z

Reserved: 2026-09-12T15:57:45.975Z

Link: CVE-2026-90567

cve-icon Vulnrichment

Updated: 2026-09-15T13:34:56.800Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T16:16:52.827

Modified: 2026-09-15T15:17:28.530

Link: CVE-2026-90567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')