CVE-2020-21321: Emlog

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.

Affected products

  • Emlog Emlog: version 6.0.0 only

Published 2021-09-15. Last modified 2026-06-17.