shiyi-blog vulnerability

A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.

Published 13 Sep 2026Updated 13 Sep 20266 sources
CVSS 5.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.