CVE-2026-21430
Severity CVSS v4.0:
HIGH
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
02/01/2026
Last modified:
16/01/2026
Description
Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scripting, leads to account takeover. As of time of publication, no known patched versions are available.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
9.30
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:emlog:emlog:2.5.23:*:*:*:pro:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



