CVE-2026-90527 | quequnlong shiyi-blog up to 1.2.1 Add Message API index.vue body.content cross site scripting (IK5RF6)
A vulnerability classified as problematic was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting.
This vulnerability is identified as CVE-2026-90527. The attack can be executed remotely. There is not any exploit available.
The project was informed of the problem early through an issue report but has not responded yet.