CVE-2026-21430: Emlog: CSRF chained with stored XSS leads to ATO
Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scripting, leads to account takeover. As of time of publication, no known patched versions are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21430?
CVE-2026-21430 is classified as a critical vulnerability due to its potential to allow cross-site request forgery attacks.
How do I fix CVE-2026-21430?
To fix CVE-2026-21430, upgrade Emlog to version 2.5.24 or later which addresses the CSRF vulnerability.
What type of attack is CVE-2026-21430 associated with?
CVE-2026-21430 is associated with cross-site request forgery (CSRF) attacks.
What are the implications of CVE-2026-21430?
Exploitation of CVE-2026-21430 could allow an attacker to post arbitrary content to an Emlog website without user consent.
Which version of Emlog is affected by CVE-2026-21430?
CVE-2026-21430 affects Emlog version 2.5.23.