Cross-Site Scripting in maliangnansheng bbs-springboot Product
CVE-2026-90563
5.1MEDIUM
What is CVE-2026-90563?
A Cross-Site Scripting (XSS) vulnerability exists in the funcction utils.toToc of ArticleController.java in the maliangnansheng bbs-springboot version 3.0.0. This flaw can be exploited remotely, allowing attackers to inject malicious scripts into web pages viewed by users, potentially leading to data theft, session hijacking, and other security breaches. Users of the affected version should take immediate action to mitigate this vulnerability.
Affected Version(s)
bbs-springboot 3.0.0
