Stored Cross-Site Scripting Vulnerability in Emlog Website Builder
CVE-2026-21431
2LOW
What is CVE-2026-21431?
Emlog, an open source website building system, contains a stored cross-site scripting vulnerability in the Resource media library function when publishing articles. This flaw allows attackers to inject script code into web pages viewable by users, potentially leading to data theft or website defacement. As of now, no patches have been released to correct this security issue.
Affected Version(s)
emlog = 2.5.23
