Cross Site Scripting Vulnerability in TDuckApp tduck-platform
CVE-2026-90528

5.1MEDIUM

Key Information:

Vendor

Tduckapp

Vendor
CVE Published:
13 September 2026

What is CVE-2026-90528?

A vulnerability exists in the TDuckApp tduck-platform, specifically in the Form Write View component located at tduck-front/src/views/form/write/index.vue. This flaw allows for remote manipulation of the argument submitShowCustomPageContent, which can lead to the execution of injected scripts in the context of the user's browser. Despite the vulnerability being reported, no response has been issued by the project maintainers, raising concerns about the security posture of the application.

Affected Version(s)

tduck-platform 5.0

tduck-platform 5.1

tduck-platform 5.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JunRoinxxX (VulDB User)
VulDB CNA Team
.