Cross-site scripting in Emlog Pro - CVE-2026-21431
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script code in a user\'s browser.
The vulnerability exists due to improper neutralization of input during web page generation in the image name field when rendering stored image names. A remote user can submit a specially crafted image name to execute arbitrary script code in a user\'s browser.