CVE-2026-34229: Emlog
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vulnerability in emlog comment module via URI scheme validation bypass. This issue has been patched in version 2.6.8.
Affected products
- Emlog Emlog: before 2.6.8 (fixed in 2.6.8)
Published 2026-04-03. Last modified 2026-07-24.