Stored Cross-Site Scripting Vulnerability in Emlog CMS by Emlog
CVE-2026-52520

5.4MEDIUM

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-52520?

Emlog CMS versions up to 2.6.14 are vulnerable to a stored cross-site scripting (XSS) flaw within the article publishing module. This vulnerability allows a remote authenticated attacker to inject malicious JavaScript code into the article content. Once submitted, and upon review or preview by an administrator in the backend, the script runs within the admin's browser session. This exploitation can lead to unauthorized administrative actions, including the creation of backdoor accounts, jeopardizing the integrity and security of the entire system.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.