Stored XSS Vulnerability in Emlog Website Building System
CVE-2026-53758
8.7HIGH
What is CVE-2026-53758?
Emlog, an open-source website building system, has a vulnerability where article content is processed by Parsedown without safe mode enabled. This flaw allows raw HTML, including tags, to be submitted through Markdown. The lack of proper sanitization exposes users to stored Cross-Site Scripting (XSS), which can be exploited by attackers to execute malicious scripts that affect all site visitors. As of the latest updates, there are no publicly known patches available to mitigate this vulnerability.
Affected Version(s)
emlog <= 2.6.29
