Cross-site scripting in Emlog Pro - CVE-2026-21432
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to take over an administrator or another user account.
The vulnerability exists due to stored cross-site scripting in Emlog Pro when rendering stored user-supplied content. A remote user can inject a specially crafted script payload to take over an administrator or another user account.
User interaction is required to view the crafted content.