CVE-2026-21430
CRITICALEmlog - CSRF
Title source: ruleDescription
Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scripting, leads to account takeover. As of time of publication, no known patched versions are available.
Scores
CVSS v3
9.3
EPSS
0.0003
EPSS Percentile
8.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Classification
CWE
CWE-352
CWE-79
Status
published
Affected Products (1)
emlog/emlog
Timeline
Published
Jan 02, 2026
Tracked Since
Feb 18, 2026