Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator reviews or previews the submitted article in the backend, the malicious script executes in the admin's browser session, allowing the attacker to perform administrative actions such as creating a backdoor administrator account.
History

Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Emlog
Emlog emlog
Vendors & Products Emlog
Emlog emlog

Wed, 05 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Stored XSS in Emlog Article Publishing Module Enables Admin Account Creation

Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Stored XSS in Emlog Article Publishing Module Enables Admin Account Creation
Weaknesses CWE-79

Mon, 03 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator reviews or previews the submitted article in the backend, the malicious script executes in the admin's browser session, allowing the attacker to perform administrative actions such as creating a backdoor administrator account.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-08-03T00:00:00.000Z

Updated: 2026-08-05T19:21:16.133Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52520

cve-icon Vulnrichment

Updated: 2026-08-05T19:21:11.388Z

cve-icon NVD

Status : Received

Published: 2026-08-03T21:16:40.390

Modified: 2026-08-05T20:17:09.743

Link: CVE-2026-52520

cve-icon Redhat

No data.