Maliangnansheng · Bbs-Springboot · CVE-2026-90563
**Name of the Vulnerable Software and Affected Versions**
maliangnansheng bbs-springboot version 3.0.0
**Description**
A remote cross site scripting issue exists within the `utils.toToc()` function of the `ArticleController.java` file. Cross site scripting is a technique where malicious scripts are injected into trusted websites, which are then executed in the browser of the user.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the use of the `utils.toToc()` function until a patch is available.