Stored Cross-Site Scripting Vulnerability in Emlog CMS by Emlog
CVE-2026-52520
5.4MEDIUM
What is CVE-2026-52520?
Emlog CMS versions up to 2.6.14 are vulnerable to a stored cross-site scripting (XSS) flaw within the article publishing module. This vulnerability allows a remote authenticated attacker to inject malicious JavaScript code into the article content. Once submitted, and upon review or preview by an administrator in the backend, the script runs within the admin's browser session. This exploitation can lead to unauthorized administrative actions, including the creation of backdoor accounts, jeopardizing the integrity and security of the entire system.
