Stored XSS Vulnerability in Emlog Website Building System
CVE-2026-53758

8.7HIGH

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-53758?

Emlog, an open-source website building system, has a vulnerability where article content is processed by Parsedown without safe mode enabled. This flaw allows raw HTML, including tags, to be submitted through Markdown. The lack of proper sanitization exposes users to stored Cross-Site Scripting (XSS), which can be exploited by attackers to execute malicious scripts that affect all site visitors. As of the latest updates, there are no publicly known patches available to mitigate this vulnerability.

Affected Version(s)

emlog <= 2.6.29

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.