Local File Inclusion Vulnerability in Emlog Website Building System
CVE-2026-34787

6.5MEDIUM

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
3 April 2026

What is CVE-2026-34787?

The Emlog website building system exhibits a Local File Inclusion (LFI) vulnerability in its admin/plugin.php file, specifically at line 80. The root cause is the improper handling of the $plugin parameter drawn from GET requests, which is utilized in the require_once function without adequate sanitization. This misconfiguration can allow attackers to exploit a bypass in the CSRF token checks, enabling them to include arbitrary PHP files from the server's filesystem. Such exploitation paves the way for potential code execution risks, compromising server integrity. As of the current date, no public patches are available to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

emlog <= 2.6.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.