Cross-site scripting in Emlog Pro - CVE-2026-53758

 

Cross-site scripting in Emlog Pro - CVE-2026-53758

Published: August 15, 2026


Vulnerability identifier: #VU142816
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-53758
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script code in victims' browsers.

The vulnerability exists due to improper neutralization of input during web page generation in Parsedown article rendering logic in include/lib/function.base.php when processing article content as Markdown. A remote user can create or edit an article containing crafted raw HTML or script content to execute arbitrary script code in victims' browsers.

The injected content is stored and rendered to site visitors, including unauthenticated visitors.


Affected software

Emlog Pro

How to mitigate CVE-2026-53758

Install security update from vendor's website.

Emlog Pro - update to 2.6.17

External References

Related Security Bulletins