CVE-2026-73850: Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Function
Published Aug 14, 2026
·Updated
Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php.
Affected Software
1 affected component
Emlog<=2.6.20
Event History
Aug 14, 2026
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-73850?
CVE-2026-73850 has a risk rating of 71, indicating a high severity level due to its potential for arbitrary SQL execution.
2
How do I fix CVE-2026-73850?
To fix CVE-2026-73850, update your Emlog software to version 2.6.21 or later, which addresses the SQL injection vulnerability in ai.php.
3
Who is affected by CVE-2026-73850?
Users of Emlog version 2.6.20 and earlier are affected by CVE-2026-73850 due to the presence of the SQL injection vulnerability.
4
What type of vulnerability is CVE-2026-73850?
CVE-2026-73850 is classified as an SQL Injection vulnerability, specifically related to the queryDatabase function in ai.php.
5
When was CVE-2026-73850 published?
CVE-2026-73850 was published on August 14, 2026.