CVE-2026-73848
Emlog: Stored XSS via Tag Name in Article Editor
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article editor. An attacker can create a tag containing ');alert(document.domain);//. The addslashes() function does not escape HTML entities, so ' is stored as-is. When the browser renders the page, it decodes ' back to a literal single quote before evaluating the JavaScript, breaking out of the string and executing arbitrary code. At time of publication, there are no publicly known patches.
| CWE | CWE-79 |
| Vendor | emlog |
| Product | emlog |
| Published | Sep 4, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for emlog emlog
Be the first to know when new unknown vulnerabilities affecting emlog emlog are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
emlog / emlog
<= 2.6.29