#VU125574 Cross-site scripting in Emlog Pro
Published: April 9, 2026 / Updated: April 10, 2026
Emlog Pro
Emlog
Description
The vulnerability allows a remote user to execute arbitrary script in an administrator context.
The vulnerability exists due to cross-site scripting in the article edit page when rendering stored custom field values. A remote user can submit specially crafted field_keys[] and field_values[] data to execute arbitrary script in an administrator context.
User interaction is required when an administrator or editor opens the article edit page.