CVE-2026-73848: Emlog
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article editor. An attacker can create a tag containing ');alert(document.domain);//. The addslashes() function does not escape HTML entities, so ' is stored as-is. When the browser renders the page, it decodes ' back to a literal single quote before evaluating the JavaScript, breaking out of the string and executing arbitrary code. At time of publication, there are no publicly known patches.
Affected products
- Emlog Emlog: up to and including 2.6.29
Published 2026-09-04. Last modified 2026-09-08.