CVE-2026-21430 – Emlog: CSRF chained with stored XSS leads to ATO
CVE ID : CVE-2026-21430
Published : Jan. 2, 2026, 7:15 p.m. | 1 hour, 9 minutes ago
Description : Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scripting, leads to account takeover. As of time of publication, no known patched versions are available.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…