CVE-2026-21430: Emlog
Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scripting, leads to account takeover. As of time of publication, no known patched versions are available.
Affected products
- Emlog Emlog: version 2.5.23 only
Published 2026-01-02. Last modified 2026-06-17.