CVE-2026-46687: Emlog

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls include View::getView($template), allowing an authenticated author to include an arbitrary local .php file when an article is viewed. No fixed version is currently identified.

Affected products

  • Emlog Emlog: up to and including 2.6.13

Published 2026-07-16. Last modified 2026-07-17.