๐Ÿ” CVE Alert

CVE-2026-73848

UNKNOWN 0.0

Emlog: Stored XSS via Tag Name in Article Editor

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article editor. An attacker can create a tag containing ');alert(document.domain);//. The addslashes() function does not escape HTML entities, so ' is stored as-is. When the browser renders the page, it decodes ' back to a literal single quote before evaluating the JavaScript, breaking out of the string and executing arbitrary code. At time of publication, there are no publicly known patches.

CWE CWE-79
Vendor emlog
Product emlog
Published Sep 4, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for emlog emlog

Be the first to know when new unknown vulnerabilities affecting emlog emlog are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

emlog / emlog
<= 2.6.29

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/emlog/emlog/security/advisories/GHSA-fv6h-wr92-v4pj