CVE-2026-21432: Emlog has stored Cross-site Scripting issue that can lead to admin or another account ATO
Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can lead to account takeover, including takeover of admin accounts. As of time of publication, no known patched versions are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21432?
CVE-2026-21432 is classified as a high severity vulnerability due to its potential for account takeover.
How does CVE-2026-21432 affect users?
CVE-2026-21432 allows an attacker to exploit a stored cross-site scripting vulnerability, potentially leading to compromised user accounts including administrative ones.
Is there a patch available for CVE-2026-21432?
As of now, there are no known patched versions available for CVE-2026-21432.
What steps can be taken to mitigate CVE-2026-21432?
To mitigate CVE-2026-21432, it is recommended to apply input validation and output encoding on user inputs and outputs.
Which version of Emlog is affected by CVE-2026-21432?
CVE-2026-21432 affects Emlog version 2.5.23.