Aller au contenu

Fiche vulnérabilité

CVE-2026-2622 : faille moyenne wangyunf blossom (CVSS 5.4)

Description

A vulnerability was detected in Blossom up to 1.17.1. This vulnerability affects the function content of the file blossom-backend/backend/src/main/java/com/blossom/backend/server/article/draft/ArticleController.java of the component Article Title Handler. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
17 févr. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • wangyunf blossom

Références

Rechercher une autre vulnérabilité dans la base CVE