CVE-2026-21430 – Emlog: CSRF chained with stored XSS leads to ATO

CVE ID : CVE-2026-21430

Published : Jan. 2, 2026, 7:15 p.m. | 1 hour, 9 minutes ago

Description : Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scripting, leads to account takeover. As of time of publication, no known patched versions are available.

Severity: 7.0 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه