CVE-2026-34229: Emlog: Stored XSS in Comment Module via URI Scheme Validation Bypass
Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vulnerability in emlog comment module via URI scheme validation bypass. This issue has been patched in version 2.6.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
emlogto a version that resolves this vulnerability.Fixed in 2.6.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34229?
CVE-2026-34229 is classified as a stored cross-site scripting (XSS) vulnerability, which is considered a high severity issue.
How do I fix CVE-2026-34229?
To fix CVE-2026-34229, upgrade to Emlog version 2.6.8 or later.
What component is affected by CVE-2026-34229?
CVE-2026-34229 affects the comment module of Emlog.
Is CVE-2026-34229 a code execution vulnerability?
No, CVE-2026-34229 is a stored XSS vulnerability, not a code execution vulnerability.
What versions of Emlog are vulnerable to CVE-2026-34229?
Emlog versions prior to 2.6.8 are vulnerable to CVE-2026-34229.