Blind SQL Injection Vulnerability in Emlog CMS Pro by Emlog
CVE-2026-53756

4.9MEDIUM

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-53756?

Emlog CMS Pro, an open source website building system, is vulnerable to a blind SQL injection. This occurs in the method User_Model::getUserDataByLogin() where the input parameter $account is inserted directly into SQL queries without sufficient validation or filtering. An attacker can exploit this weakness via the authentication cookie validation process. The vulnerability arises when $username extracted from the cookie is passed into SQL queries in an unfiltered manner, relying solely on an HMAC signature for security, which can potentially be forged. This security issue has been addressed in version 2.6.16 of Emlog CMS Pro.

Affected Version(s)

emlog < 2.6.16

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.